CVE-2026-39304 - Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incorrect handling of TLSv1.3 KeyUpdate can be exploited to cause DoS via OOM
CVE ID :CVE-2026-39304
Published : April 10, 2026, 11:16 a.m. | 2 hours, 49 minutes ago
Description :Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache Activ...
Related Vulnerabilities
- CVE-2026-34500: CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled a MEDIUM
- CVE-2026-39304: Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, HIGH
- CVE-2026-35661: OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Telegram callback query MEDIUM
- CVE-2026-34477: The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: i MEDIUM
- CVE-2026-35653: OpenClaw before 2026.3.24 contains an incorrect authorization vulnerability in the POST /reset-profi HIGH
Related Coverage
Threat Actors