Known Vulnerabilities for Artemis by Apache
Listed below are 10 of the newest known vulnerabilities associated with "Artemis" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-86404 json | EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStr... | Not Provided | 2026-09-07 | 2026-09-09 |
| CVE-2026-75880 json | An authenticated client could attach a consumer with a selector containing crafted wildcard usage that results in excessive e... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-67593 json | A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-57967 json | An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-57822 json | When the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-49364 json | An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the ... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-49363 json | An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBE... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-49362 json | An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker ... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-42527 json | Deserialization of Untrusted Data vulnerability in Apache Camel. The default ObjectInputFilter pattern shipped with several ... | Not Provided | 2026-07-06 | 2026-07-06 |
| CVE-2026-41001 json | Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data di... | Not Provided | 2026-06-11 | 2026-06-23 |