Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getFederationPolicy(). The method calls Class.forName(clazz).getConstructor().newInstance() where clazz is read directly from the CORE protocol wire buffer without type validation. An authenticated federation peer can send a FEDERATION_DOWNSTREAM_CONNECT packet with a crafted class name, causing the broker to load and instantiate arbitrary classes visible to the Artemis module classloader. Static initializers (<clinit>) and no-argument constructors (<init>()) execute as side effects before the type cast, enabling denial of service via system-property poisoning, out-of-memory conditions via classloading, or broker state manipulation.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 28 Sep 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getFederationPolicy(). The method calls Class.forName(clazz).getConstructor().newInstance() where clazz is read directly from the CORE protocol wire buffer without type validation. An authenticated federation peer can send a FEDERATION_DOWNSTREAM_CONNECT packet with a crafted class name, causing the broker to load and instantiate arbitrary classes visible to the Artemis module classloader. Static initializers (<clinit>) and no-argument constructors (<init>()) execute as side effects before the type cast, enabling denial of service via system-property poisoning, out-of-memory conditions via classloading, or broker state manipulation. | |
| Title | Artemis-core-client: unsafe reflection in apache activemq artemis federation message deserialization | |
| First Time appeared |
Redhat
Redhat amq Broker Redhat jboss Enterprise Application Platform |
|
| Weaknesses | CWE-470 | |
| CPEs | cpe:/a:redhat:amq_broker:7 cpe:/a:redhat:jboss_enterprise_application_platform:7 |
|
| Vendors & Products |
Redhat
Redhat amq Broker Redhat jboss Enterprise Application Platform |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-28T13:10:33.668Z
Reserved: 2026-09-28T12:37:20.491Z
Link: CVE-2026-101292
No data.
Status : Received
Published: 2026-09-28T13:17:21.267
Modified: 2026-09-28T13:17:21.267
Link: CVE-2026-101292
No data.
OpenCVE Enrichment
No data.
Weaknesses