CVE-2026-39304 - Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incorrect handling of TLSv1.3 KeyUpdate can be exploited to cause DoS via OOM
CVE ID :CVE-2026-39304
Published : April 10, 2026, 11:16 a.m. | 2 hours, 49 minutes ago
Description :Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache Activ...
Related Vulnerabilities
- CVE-2026-34500: CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled a MEDIUM
- CVE-2026-24880: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Ap MEDIUM
- CVE-2026-40021: Apache Log4net's XmlLayout https://logging.apache.org/log4net/manual/configuration/layouts.html#layo MEDIUM
- CVE-2026-34481: Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout. MEDIUM
- CVE-2026-5460: A heap use-after-free exists in wolfSSL's TLS 1.3 post-quantum cryptography (PQC) hybrid KeyShare pr MEDIUM
Related Coverage
Threat Actors