CVE-2026-75880
Analyzed Analyzed - Analysis Complete

Denial of Service in Apache Artemis via Wildcard Selector

Vulnerability report for CVE-2026-75880, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-18

Assigner: Apache Software Foundation

Description

An authenticated client could attach a consumer with a selector containing crafted wildcard usage that results in excessive evaluation during message delivery attempts, occupying a shared broker thread and leading to denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-18
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
apache artemis From 2.50.0 (inc) to 2.57.0 (exc)
apache artemis From 1.0.0 (inc) to 2.44.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1333 The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an authenticated client to attach a consumer with a message selector containing crafted wildcards. This causes excessive evaluation during message delivery attempts, consuming shared broker threads and leading to a denial of service.

Detection Guidance

Detecting this vulnerability requires checking Apache Artemis or ActiveMQ Artemis versions and monitoring for unusual consumer activity with crafted wildcards. Check installed versions with commands like 'artemis version' or 'activemq-artemis version'. Inspect broker logs for excessive thread usage or failed message deliveries. Monitor network traffic for abnormal consumer attachment patterns.

Impact Analysis

It can cause system slowdowns or crashes by consuming all available broker threads, disrupting message delivery for all users and services relying on the affected Apache Artemis or ActiveMQ Artemis versions.

Compliance Impact

This vulnerability could impact compliance with standards like GDPR and HIPAA by enabling denial of service attacks that disrupt system availability. Such disruptions may violate requirements for data accessibility and processing integrity in regulated environments.

Mitigation Strategies

Upgrade Apache Artemis to version 2.57.0 or later and Apache ActiveMQ Artemis to version 2.45.0 or later to address the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75880. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart