Executive brief
Apache ActiveMQ is a popular open-source message broker used to facilitate communication between different software applications. A vulnerability in its web console API allows attackers to inject malicious content or manipulate security headers by sending specially crafted messages. This could lead to unauthorized actions being performed in a user's browser or the bypass of security protections, potentially compromising sensitive data or administrative sessions.
Technical details
A Cross-Site Scripting (XSS) and HTTP response header injection vulnerability exists in the MessageServlet component of the Apache ActiveMQ web console API. The root cause is the lack of validation when the servlet copies JMS message properties directly into HTTP response headers. A remote attacker can exploit this by sending a JMS message with malicious properties that, when retrieved via the API, inject or overwrite security headers or execute scripts in the context of the user's browser. The vulnerability is fixed in versions 5.19.7 and 6.2.6, where MessageServlet has been deprecated and disabled by default.
Affected products
- Apache ActiveMQ < 5.19.7, >= 6.0.0 < 6.2.6
- Apache ActiveMQ Web < 5.19.7, >= 6.0.0 < 6.2.6
Timeline
- 2026-05-31: disclosed: Initial disclosure on oss-security mailing list
- 2026-06-01: advisory: NVD and GitHub Advisory published
- 2026-06-01: patched: Fixes released in versions 5.19.7 and 6.2.6