- Issued:
- 2026-09-10
- Updated:
- 2026-09-10
RHSA-2026:66488 - Security Advisory
Synopsis
Important: Red Hat AMQ Broker 7.14.1 release and security update
Type/Severity
Security Advisory: Important
Topic
Red Hat AMQ Broker 7.14.1 is now available from the Red Hat Customer Portal.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Description
AMQ Broker is a high-performance messaging implementation based on ActiveMQ Artemis. It uses an asynchronous journal for fast message persistence, and supports multiple languages, protocols, and platforms.
This release of Red Hat AMQ Broker 7.14.1 includes security and bug fixes, and enhancements. For further information, refer to the release notes linked to in the References section.
Security Fix(es):
- (CVE-2025-14813) bcprov-jdk18on: GOSTCTR implementation unable to process more than 255 blocks correctly
- (CVE-2026-0636) bcprov-jdk18on: LDAP injection vulnerability in LDAPStoreHelper.java
- (CVE-2026-10050) jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision
- (CVE-2026-12143) form-data: form-data: Form field override via CRLF injection
- (CVE-2026-12151) undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames
- (CVE-2026-13149) brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity
- (CVE-2026-13676) fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization
- (CVE-2026-40983) micrometer-core: Micrometer: Denial of Service via specially crafted gRPC requests
- (CVE-2026-40984) micrometer-core: Micrometer: Denial of Service via specially crafted HTTP requests
- (CVE-2026-42198) postgresql: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication
- (CVE-2026-42264) axios: Axios: Prototype pollution allows information disclosure and request manipulation
- (CVE-2026-42338) ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input
- (CVE-2026-42578) netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation
- (CVE-2026-42581) netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers
- (CVE-2026-42583) netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder
- (CVE-2026-42584) netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion
- (CVE-2026-42587) netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression
- (CVE-2026-42587) netty-codec-http: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression
- (CVE-2026-42588) activemq-broker: Apache ActiveMQ: Arbitrary code execution via improper input validation in Jolokia JMX-HTTP bridge
- (CVE-2026-44248) netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 header
- (CVE-2026-44249) netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation
- (CVE-2026-44486) axios: Axios: Information disclosure of proxy credentials via HTTP redirects
- (CVE-2026-44487) axios: Axios: Information disclosure of proxy credentials via redirect flows
- (CVE-2026-44488) axios: Axios: Denial of Service due to unenforced request and response size limits
- (CVE-2026-44492) axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization
- (CVE-2026-44494) axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution
- (CVE-2026-44496) axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name
- (CVE-2026-44893) netty-codec-haproxy: Netty-codec-haproxy: Denial of Service via malformed HAProxy message
- (CVE-2026-45205) commons-configuration2: Apache Commons Configuration: Denial of Service via uncontrolled recursion with crafted YAML input
- (CVE-2026-45416) netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake
- (CVE-2026-45736) ws: ws: Uninitialized memory disclosure via `websocket.close()` with `TypedArray`
- (CVE-2026-48043) netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak
- (CVE-2026-48059) netty-codec-haproxy: Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers
- (CVE-2026-48779) ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments
- (CVE-2026-49362) artemis-server: artemis core protocol permits unauthed queue creation
- (CVE-2026-49364) artemis-server: artemis cluster password leak via jgroups spoof
- (CVE-2026-49432) artemis-stomp-protocol: Apache ActiveMQ: Denial of Service via improper input validation in STOMP connector
- (CVE-2026-49978) dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution
- (CVE-2026-50010) netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass
- (CVE-2026-50734) activemq-client: Apache ActiveMQ: Denial of Service via crafted WireFormatInfo frame
- (CVE-2026-53916) artemis-stomp-protocol: Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header buffer in STOMP NIO codec
- (CVE-2026-54512) jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass
- (CVE-2026-54513) jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
- (CVE-2026-55831) netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing
- (CVE-2026-55833) netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification
- (CVE-2026-55851) netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message
- (CVE-2026-5588) bcpkix-jdk18on: PKIX draft CompositeVerifier accepts empty signature sequence as valid
- (CVE-2026-56745) netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec
- (CVE-2026-56746) netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header
- (CVE-2026-56819) netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak
- (CVE-2026-57967) artemis-server: Apache Artemis — session hijack via missing authentication
- (CVE-2026-59869) js-yaml: js-yaml: Denial of Service via crafted YAML documents
- (CVE-2026-59873) tar: node-tar: Denial of Service via crafted gzip bomb
- (CVE-2026-59874) tar: Node-tar: Denial of Service via malformed tar archive header
- (CVE-2026-59899) netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb)
- (CVE-2026-62243) netty-handler: Netty: TLS hostname verification bypass via OpenSSL client path misconfiguration
- (CVE-2026-66257) proton-j: Apache Qpid Proton-J: Denial of Service via unbounded symbol value caching
- (CVE-2026-66273) proton-j: Apache Qpid Proton-J: Denial of Service due to excessive allocation
- (CVE-2026-66274) amq-broker-maven-repository.zip: Apache Qpid Proton-J: Denial of Service via unbounded type nesting
- (CVE-2026-66274) amq-broker-bin.zip: Apache Qpid Proton-J: Denial of Service via unbounded type nesting
- (CVE-2026-67593) artemis-openwire-protocol: AMQ Broker Artemis: pre-authentication arbitrary durable queue deletion via OpenWire RemoveSubscriptionInfo
- (CVE-2026-68494) amq-broker-bin.zip: jackson-core: Denial of Service via incomplete fix in async JSON parser
- (CVE-2026-68494) amq-broker-maven-repository.zip: jackson-core: Denial of Service via incomplete fix in async JSON parser
- (CVE-2026-9595) webpack-dev-server: webpack-dev-server: Information disclosure and denial of service via improper proxy configuration
- (CVE-2026-10051) jetty-server: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections
- (CVE-2026-34478) log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames
- (CVE-2026-34480) log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging
- (CVE-2026-34481) log4j-layout-template-json: Apache Log4j JsonTemplateLayout: Denial of Service via invalid JSON output
- (CVE-2026-49363) artemis-server: artemis-server: Pre-auth topology disclosure via CORE SUBSCRIBE_TOPOLOGY_V2 on channel0
- (CVE-2026-57822) artemis-core-client: activemq-artemis: Unsafe deserialization via JsonUtil CompositeData on management address
For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Solution
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings.
The References section of this erratum contains a download link (you must log in to download the update).
Affected Products
- Red Hat JBoss Middleware Text-Only Advisories for MIDDLEWARE 1 x86_64
Fixes
- BZ - 2457321 - CVE-2026-34481 org.apache.logging.log4j: Apache Log4j JsonTemplateLayout: Denial of Service via invalid JSON output
- BZ - 2457323 - CVE-2026-34478 org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames
- BZ - 2457328 - CVE-2026-34480 org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging
- BZ - 2458634 - CVE-2026-5588 bouncycastle: BC-JAVA: PKIX draft CompositeVerifier accepts empty signature sequence as valid
- BZ - 2458640 - CVE-2025-14813 bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly
- BZ - 2458641 - CVE-2026-0636 bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java
- BZ - 2463857 - CVE-2026-42198 jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication
- BZ - 2467927 - CVE-2026-42264 axios: Axios: Prototype pollution allows information disclosure and request manipulation
- BZ - 2476810 - CVE-2026-42338 ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input
- BZ - 2477219 - CVE-2026-42583 netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder
- BZ - 2477220 - CVE-2026-42587 netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression
- BZ - 2477224 - CVE-2026-42584 netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion
- BZ - 2477226 - CVE-2026-42578 netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation
- BZ - 2477231 - CVE-2026-44248 netty: io.netty/netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 header
- BZ - 2477232 - CVE-2026-42581 netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers
- BZ - 2477425 - CVE-2026-45205 commons-configuration: Apache Commons Configuration: Denial of Service via uncontrolled recursion with crafted YAML input
- BZ - 2477914 - CVE-2026-45736 ws: ws: Uninitialized memory disclosure via `websocket.close()` with `TypedArray`
- BZ - 2477945 - CVE-2026-49362 artemis-server: undertow-core: wildfly-messaging-activemq-subsystem: artemis core protocol permits unauthed queue creation
- BZ - 2478013 - CVE-2026-49364 wildfly-messaging-activemq-subsystem: artemis-server: jgroups: artemis cluster password leak via jgroups spoof
- BZ - 2480638 - CVE-2026-57967 artemis-server: Apache Artemis ? session hijack via missing authentication
- BZ - 2486488 - CVE-2026-42588 org.apache.activemq/activemq-broker: org.apache.activemq/activemq-all: org.apache.activemq/apache-activemq: Apache ActiveMQ: Arbitrary code execution via improper input validation in Jolokia JMX-HTTP bridge
- BZ - 2486697 - CVE-2026-40983 micrometer: micrometer-core: Micrometer: Denial of Service via specially crafted gRPC requests
- BZ - 2486716 - CVE-2026-40984 micrometer-core: micrometer-jetty11: micrometer-jetty12: Micrometer: Denial of Service via specially crafted HTTP requests
- BZ - 2487938 - CVE-2026-44492 axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization
- BZ - 2487942 - CVE-2026-44494 axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution
- BZ - 2487943 - CVE-2026-44496 axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name
- BZ - 2487947 - CVE-2026-44486 axios: Axios: Information disclosure of proxy credentials via HTTP redirects
- BZ - 2487948 - CVE-2026-44487 axios: Axios: Information disclosure of proxy credentials via redirect flows
- BZ - 2487949 - CVE-2026-44488 axios: Axios: Denial of Service due to unenforced request and response size limits
- BZ - 2488081 - CVE-2026-44249 netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation
- BZ - 2488383 - CVE-2026-44893 netty-codec-haproxy: Netty-codec-haproxy: Denial of Service via malformed HAProxy message
- BZ - 2488391 - CVE-2026-45416 netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake
- BZ - 2488429 - CVE-2026-50010 netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass
- BZ - 2488437 - CVE-2026-48059 netty-codec-haproxy: Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers
- BZ - 2488442 - CVE-2026-48043 netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak
- BZ - 2488480 - CVE-2026-12143 form-data: form-data: Form field override via CRLF injection
- BZ - 2488934 - CVE-2026-9595 webpack-dev-server: webpack-dev-server: Information disclosure and denial of service via improper proxy configuration
- BZ - 2489661 - CVE-2026-48779 ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments
- BZ - 2489980 - CVE-2026-12151 undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames
- BZ - 2492010 - CVE-2026-54513 jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
- BZ - 2492015 - CVE-2026-54512 jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass
- BZ - 2492627 - CVE-2026-49363 artemis-server: artemis-server: Pre-auth topology disclosure via CORE SUBSCRIBE_TOPOLOGY_V2 on channel0
- BZ - 2494197 - CVE-2026-13676 fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization
- BZ - 2494813 - CVE-2026-13149 brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity
- BZ - 2494841 - CVE-2026-50734 Apache ActiveMQ Client: Apache ActiveMQ: Apache ActiveMQ All: Apache ActiveMQ: Denial of Service via crafted WireFormatInfo frame
- BZ - 2494846 - CVE-2026-53916 activemq-stomp: Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header buffer in STOMP NIO codec
- BZ - 2494847 - CVE-2026-49432 org.apache.activemq/activemq: org.apache.activemq/activemq-all: org.apache.activemq/activemq-stomp: Apache ActiveMQ: Denial of Service via improper input validation in STOMP connector
- BZ - 2495823 - CVE-2026-57822 artemis-core-client: activemq-artemis: Unsafe deserialization via JsonUtil CompositeData on management address
- BZ - 2498116 - CVE-2026-59874 tar: Node-tar: Denial of Service via malformed tar archive header
- BZ - 2498120 - CVE-2026-59873 tar: node-tar: Denial of Service via crafted gzip bomb
- BZ - 2498122 - CVE-2026-59869 js-yaml: js-yaml: Denial of Service via crafted YAML documents
- BZ - 2499928 - CVE-2026-10051 jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections
- BZ - 2500695 - CVE-2026-49978 dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution
- BZ - 2503101 - CVE-2026-55833 netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification
- BZ - 2503103 - CVE-2026-55831 io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing
- BZ - 2505422 - CVE-2026-56746 io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header
- BZ - 2505698 - CVE-2026-55851 io.netty/netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message
- BZ - 2505911 - CVE-2026-56745 netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec
- BZ - 2505980 - CVE-2026-56819 io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak
- BZ - 2507482 - CVE-2026-59899 io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb)
- BZ - 2510277 - CVE-2026-67593 artemis-openwire-protocol: AMQ Broker Artemis: pre-authentication arbitrary durable queue deletion via OpenWire RemoveSubscriptionInfo
- BZ - 2511026 - CVE-2026-68494 com.fasterxml.jackson.core/jackson-core: tools.jackson.core/jackson-core: jackson-core: Denial of Service via incomplete fix in async JSON parser
- BZ - 2511322 - CVE-2026-66273 org.apache.qpid/proton-j: Apache Qpid Proton-J: Denial of Service due to excessive allocation
- BZ - 2511326 - CVE-2026-66257 qpid-proton-j: Apache Qpid Proton-J: Denial of Service via unbounded symbol value caching
- BZ - 2511337 - CVE-2026-66274 org.apache.qpid/proton-j: Apache Qpid Proton-J: Denial of Service via unbounded type nesting
- BZ - 2521309 - CVE-2026-62243 io.netty/netty-handler: Netty: TLS hostname verification bypass via OpenSSL client path misconfiguration
- ENTMQBR-10810 - Large message size set to 0 with DLQ/Expiry and mirror enabled
- ENTMQBR-10935 - [7.14] Message loss and missing store-and-forward queue following graceful node restart in a symmetric cluster under high production load
- ENTMQBR-10911 - [7.14] LargeMessageInterruptTest.killProcess() relies on non-portable kill -SIGINT flag
- ENTMQBR-10732 - The CLI perf client command doesn't close the connection factory
- ENTMQBR-10990 - [7.14] HTTP tunneling server async packets starve request replies
- ENTMQBR-10632 - AMQ broker threw NPE during restart when calling ActiveMQServerImpl.recoverStoredDiverts
- ENTMQBR-10635 - Deadlock in the ClientSessionFactoryImpl
- ENTMQBR-10650 - MQTT address is auto-deleted despite having an attached queue
- ENTMQBR-10730 - Avoid reflection on Downstream core federation. Using Direct instantiation instead.
- ENTMQBR-10731 - The CLI transfer command doesn't close the connection factory
CVEs
- CVE-2025-14813
- CVE-2026-0636
- CVE-2026-5588
- CVE-2026-9595
- CVE-2026-10050
- CVE-2026-10051
- CVE-2026-12143
- CVE-2026-12151
- CVE-2026-13149
- CVE-2026-13676
- CVE-2026-34478
- CVE-2026-34480
- CVE-2026-34481
- CVE-2026-40983
- CVE-2026-40984
- CVE-2026-42198
- CVE-2026-42264
- CVE-2026-42338
- CVE-2026-42578
- CVE-2026-42581
- CVE-2026-42583
- CVE-2026-42584
- CVE-2026-42587
- CVE-2026-42588
- CVE-2026-44248
- CVE-2026-44249
- CVE-2026-44486
- CVE-2026-44487
- CVE-2026-44488
- CVE-2026-44492
- CVE-2026-44494
- CVE-2026-44496
- CVE-2026-44893
- CVE-2026-45205
- CVE-2026-45416
- CVE-2026-45736
- CVE-2026-48043
- CVE-2026-48059
- CVE-2026-48779
- CVE-2026-49362
- CVE-2026-49363
- CVE-2026-49364
- CVE-2026-49432
- CVE-2026-49978
- CVE-2026-50010
- CVE-2026-50734
- CVE-2026-53916
- CVE-2026-54512
- CVE-2026-54513
- CVE-2026-55831
- CVE-2026-55833
- CVE-2026-55851
- CVE-2026-56745
- CVE-2026-56746
- CVE-2026-56819
- CVE-2026-57822
- CVE-2026-57967
- CVE-2026-59869
- CVE-2026-59873
- CVE-2026-59874
- CVE-2026-59899
- CVE-2026-62243
- CVE-2026-66257
- CVE-2026-66273
- CVE-2026-66274
- CVE-2026-67593
- CVE-2026-68494
References
- https://access.redhat.com/security/updates/classification/#important
- https://access.redhat.com/security/updates/classification#important
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=jboss.amq.broker&version=7.14.1
- https://docs.redhat.com/en/documentation/red_hat_amq_broker/7.14
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.