<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>ActiveMQ Artemis (&lt; 2.34.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/activemq-artemis--2.34.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 28 Sep 2026 14:15:05 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/activemq-artemis--2.34.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unsafe Reflection Vulnerability in Apache ActiveMQ Artemis</title><link>https://feed.craftedsignal.io/briefs/2026-09-activemq-artemis-reflection/</link><pubDate>Mon, 28 Sep 2026 14:15:05 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-activemq-artemis-reflection/</guid><description>Apache ActiveMQ Artemis versions prior to 2.34.0 are vulnerable to remote code execution or state manipulation via insecure reflection in the FederationStreamConnectMessage.getFederationPolicy() method.</description><content:encoded><![CDATA[<p>Apache ActiveMQ Artemis versions prior to 2.34.0 are susceptible to an unsafe reflection vulnerability residing within the FederationStreamConnectMessage.getFederationPolicy() method. The vulnerability arises because the class name (clazz) is read directly from the CORE protocol wire buffer without undergoing sufficient type validation before being passed to Class.forName(clazz).getConstructor().newInstance().</p>
<p>An authenticated attacker acting as a federation peer can transmit a specifically crafted FEDERATION_DOWNSTREAM_CONNECT packet to the broker. This packet forces the broker to instantiate arbitrary classes accessible within the Artemis module classloader. As a side effect of this instantiation, static initializers and no-argument constructors are executed. This behavior allows for malicious outcomes, including denial of service, memory exhaustion through excessive classloading, or unauthorized modification of the broker's internal state. This vulnerability poses a significant risk to the integrity and availability of message brokers configured for federation in enterprise environments.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an authenticated peer to trigger arbitrary class instantiation within the broker's process. This can lead to system-wide denial of service, resource exhaustion, and potential compromise of the broker state. Given the role of ActiveMQ in enterprise messaging, this could disrupt critical business processes and data flow across internal and hybrid infrastructure.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade Apache ActiveMQ Artemis to version 2.34.0 or later immediately to resolve the reflection flaw.</li>
<li>Restrict federation configuration to trusted peers only and implement strict network access controls to limit access to the CORE protocol ports.</li>
<li>Conduct an audit of existing federation setups to identify and remove unauthorized or unknown federation peers.</li>
<li>Enable protocol-level logging to capture traffic patterns associated with FEDERATION_DOWNSTREAM_CONNECT packets for forensic analysis.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>deserialization</category><category>message-broker</category></item></channel></rss>