CVE-2026-57822
Analyzed Analyzed - Analysis Complete

Denial of Service via Java Deserialization in Apache Artemis

Vulnerability report for CVE-2026-57822, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-16

Assigner: Apache Software Foundation

Description

When the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized with MANAGE permission to perform management-via-messaging, the parameter processing can trigger Java deserialization of certain method parameters that the broker will not utilise. The permitted types allow to craft a payload causing excessive computation and pinning the processing thread, leading to denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.3.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-16
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
apache artemis From 2.50.0 (inc) to 2.57.0 (exc)
apache artemis From 1.3.0 (inc) to 2.44.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves Java deserialization in Apache Artemis and ActiveMQ Artemis when processing message-based management requests. Authenticated clients with MANAGE permissions can send crafted parameters that trigger excessive computation, pinning processing threads and causing a denial of service.

Detection Guidance

This vulnerability involves Java deserialization leading to denial of service in Apache Artemis and ActiveMQ Artemis. Detection requires checking the software version and monitoring for unusual thread behavior or excessive CPU usage during message processing. No specific commands are provided in the context.

Impact Analysis

The vulnerability can lead to system downtime as the broker becomes unresponsive due to pinned threads. It requires an attacker to have authenticated access with MANAGE permissions, but once exploited, it disrupts normal operations by consuming excessive resources.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by enabling denial of service attacks through excessive computation and thread pinning. Such attacks may disrupt critical services handling sensitive data, potentially violating availability requirements in GDPR Article 32 and HIPAA Security Rule Section 164.308(a)(7).

Mitigation Strategies

Upgrade Apache Artemis to version 2.57.0 or later and Apache ActiveMQ Artemis to version 2.45.0 or later to address the Java deserialization issue causing denial of service.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-57822. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart