{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/activemq-artemis--2.34.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:apache:activemq_artemis:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-101292"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ActiveMQ Artemis (\u003c 2.34.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","deserialization","message-broker"],"_cs_type":"advisory","_cs_vendors":["Apache"],"content_html":"\u003cp\u003eApache ActiveMQ Artemis versions prior to 2.34.0 are susceptible to an unsafe reflection vulnerability residing within the FederationStreamConnectMessage.getFederationPolicy() method. The vulnerability arises because the class name (clazz) is read directly from the CORE protocol wire buffer without undergoing sufficient type validation before being passed to Class.forName(clazz).getConstructor().newInstance().\u003c/p\u003e\n\u003cp\u003eAn authenticated attacker acting as a federation peer can transmit a specifically crafted FEDERATION_DOWNSTREAM_CONNECT packet to the broker. This packet forces the broker to instantiate arbitrary classes accessible within the Artemis module classloader. As a side effect of this instantiation, static initializers and no-argument constructors are executed. This behavior allows for malicious outcomes, including denial of service, memory exhaustion through excessive classloading, or unauthorized modification of the broker's internal state. This vulnerability poses a significant risk to the integrity and availability of message brokers configured for federation in enterprise environments.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated peer to trigger arbitrary class instantiation within the broker's process. This can lead to system-wide denial of service, resource exhaustion, and potential compromise of the broker state. Given the role of ActiveMQ in enterprise messaging, this could disrupt critical business processes and data flow across internal and hybrid infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade Apache ActiveMQ Artemis to version 2.34.0 or later immediately to resolve the reflection flaw.\u003c/li\u003e\n\u003cli\u003eRestrict federation configuration to trusted peers only and implement strict network access controls to limit access to the CORE protocol ports.\u003c/li\u003e\n\u003cli\u003eConduct an audit of existing federation setups to identify and remove unauthorized or unknown federation peers.\u003c/li\u003e\n\u003cli\u003eEnable protocol-level logging to capture traffic patterns associated with FEDERATION_DOWNSTREAM_CONNECT packets for forensic analysis.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-28T14:15:05Z","date_published":"2026-09-28T14:15:05Z","id":"https://feed.craftedsignal.io/briefs/2026-09-activemq-artemis-reflection/","summary":"Apache ActiveMQ Artemis versions prior to 2.34.0 are vulnerable to remote code execution or state manipulation via insecure reflection in the FederationStreamConnectMessage.getFederationPolicy() method.","title":"Unsafe Reflection Vulnerability in Apache ActiveMQ Artemis","url":"https://feed.craftedsignal.io/briefs/2026-09-activemq-artemis-reflection/"}],"language":"en","title":"CraftedSignal Threat Feed - ActiveMQ Artemis (\u003c 2.34.0)","version":"https://jsonfeed.org/version/1.1"}