{
	"document":{
		"aggregate_severity":{
			"namespace":"https://nvd.nist.gov/vuln-metrics/cvss",
			"text":"High"
		},
		"category":"csaf_vex",
		"csaf_version":"2.0",
		"distribution":{
			"tlp":{
				"label":"WHITE",
				"url":"https:/www.first.org/tlp/"
			}
		},
		"lang":"en",
		"notes":[
			{
				"text":"activemq security update",
				"category":"general",
				"title":"Synopsis"
			},
			{
				"text":"An update for activemq is now available for openEuler-24.03-LTS-SP1",
				"category":"general",
				"title":"Summary"
			},
			{
				"text":"The most popular and powerful open source messaging and Integration Patterns server.\n\nSecurity Fix(es):\n\nImproper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All.\n\nA remote unauthenticated peer that can reach an exposed AMQP NIO connector can trigger denial-of-service behavior by sending a frame size value. This cause the NIO threads to die and if done rapidly enough can lead to exhaustion of the NIO thread pool denying service to other connections.\nThis issue affects Apache ActiveMQ AMQP: before 5.19.9, from 6.0.0 before 6.2.8; Apache ActiveMQ: before 5.19.9, from 6.0.0 before 6.2.8; Apache ActiveMQ All: before 5.19.9, from 6.0.0 before 6.2.8.\n\nUsers are recommended to upgrade to version 5.19.9, 6.2.8, or 6.3.0 which fixes the issue.(CVE-2026-59878)\n\nImproper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.\n\n An authenticated low-privilege user can bypass a per-destination\nwrite ACL by sending to an ActiveMQ temporary composite destination whose physical name is a\ncomma-separated composite of real queues. This allows publishing messages to any of the destinations in the list without proper write ACL permissions because the authorization check is bypassed due to the composite destination being marked as temporary.\nThis issue affects Apache ActiveMQ Broker: before 5.19.9, from 6.0.0 before 6.2.8; Apache ActiveMQ All: before 5.19.9, from 6.0.0 before 6.2.8; Apache ActiveMQ: before 5.19.9, from 6.0.0 before 6.2.8.\n\nUsers are recommended to upgrade to version 5.19.9, 6.2.8 or 6.3.0, which fixes the issue.(CVE-2026-61487)",
				"category":"general",
				"title":"Description"
			},
			{
				"text":"An update for activemq is now available for master/openEuler-20.03-LTS-SP4/openEuler-22.03-LTS-SP4/openEuler-24.03-LTS-Next/openEuler-24.03-LTS-SP1/openEuler-24.03-LTS-SP3/openEuler-24.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.",
				"category":"general",
				"title":"Topic"
			},
			{
				"text":"High",
				"category":"general",
				"title":"Severity"
			},
			{
				"text":"activemq",
				"category":"general",
				"title":"Affected Component"
			}
		],
		"publisher":{
			"issuing_authority":"openEuler security committee",
			"name":"openEuler",
			"namespace":"https://www.openeuler.org",
			"contact_details":"openeuler-security@openeuler.org",
			"category":"vendor"
		},
		"references":[
			{
				"summary":"openEuler-SA-2026-3265",
				"category":"self",
				"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3265"
			},
			{
				"summary":"CVE-2026-59878",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-59878&packageName=activemq"
			},
			{
				"summary":"CVE-2026-61487",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-61487&packageName=activemq"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59878"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61487"
			},
			{
				"summary":"openEuler-SA-2026-3265 vex file",
				"category":"self",
				"url":"https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-3265.json"
			}
		],
		"title":"An update for activemq is now available for openEuler-24.03-LTS-SP1",
		"tracking":{
			"initial_release_date":"2026-08-11T10:45:58+08:00",
			"revision_history":[
				{
					"date":"2026-08-11T10:45:58+08:00",
					"summary":"Initial",
					"number":"1.0.0"
				}
			],
			"generator":{
				"date":"2026-08-11T10:45:58+08:00",
				"engine":{
					"name":"openEuler CSAF Tool V1.0"
				}
			},
			"current_release_date":"2026-08-11T10:45:58+08:00",
			"id":"openEuler-SA-2026-3265",
			"version":"1.0.0",
			"status":"final"
		}
	},
	"product_tree":{
		"branches":[
			{
				"name":"openEuler",
				"category":"vendor",
				"branches":[
					{
						"name":"openEuler",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP1"
									},
									"product_id":"openEuler-24.03-LTS-SP1",
									"name":"openEuler-24.03-LTS-SP1"
								},
								"name":"openEuler-24.03-LTS-SP1",
								"category":"product_version"
							}
						],
						"category":"product_name"
					},
					{
						"name":"src",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP1"
									},
									"product_id":"activemq-5.19.9-1.oe2403sp1.src.rpm",
									"name":"activemq-5.19.9-1.oe2403sp1.src.rpm"
								},
								"name":"activemq-5.19.9-1.oe2403sp1.src.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					},
					{
						"name":"noarch",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP1"
									},
									"product_id":"activemq-5.19.9-1.oe2403sp1.noarch.rpm",
									"name":"activemq-5.19.9-1.oe2403sp1.noarch.rpm"
								},
								"name":"activemq-5.19.9-1.oe2403sp1.noarch.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP1"
									},
									"product_id":"activemq-javadoc-5.19.9-1.oe2403sp1.noarch.rpm",
									"name":"activemq-javadoc-5.19.9-1.oe2403sp1.noarch.rpm"
								},
								"name":"activemq-javadoc-5.19.9-1.oe2403sp1.noarch.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					}
				]
			}
		],
		"relationships":[
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP1",
				"product_reference":"activemq-5.19.9-1.oe2403sp1.src.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP1:activemq-5.19.9-1.oe2403sp1.src",
					"name":"activemq-5.19.9-1.oe2403sp1.src as a component of openEuler-24.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP1",
				"product_reference":"activemq-5.19.9-1.oe2403sp1.noarch.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP1:activemq-5.19.9-1.oe2403sp1.noarch",
					"name":"activemq-5.19.9-1.oe2403sp1.noarch as a component of openEuler-24.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP1",
				"product_reference":"activemq-javadoc-5.19.9-1.oe2403sp1.noarch.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP1:activemq-javadoc-5.19.9-1.oe2403sp1.noarch",
					"name":"activemq-javadoc-5.19.9-1.oe2403sp1.noarch as a component of openEuler-24.03-LTS-SP1"
				},
				"category":"default_component_of"
			}
		]
	},
	"vulnerabilities":[
		{
			"cve":"CVE-2026-59878",
			"notes":[
				{
					"text":"Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All.\n\nA remote unauthenticated peer that can reach an exposed AMQP NIO connector can trigger denial-of-service behavior by sending a frame size value. This cause the NIO threads to die and if done rapidly enough can lead to exhaustion of the NIO thread pool denying service to other connections.\nThis issue affects Apache ActiveMQ AMQP: before 5.19.9, from 6.0.0 before 6.2.8; Apache ActiveMQ: before 5.19.9, from 6.0.0 before 6.2.8; Apache ActiveMQ All: before 5.19.9, from 6.0.0 before 6.2.8.\n\nUsers are recommended to upgrade to version 5.19.9, 6.2.8, or 6.3.0 which fixes the issue.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP1:activemq-5.19.9-1.oe2403sp1.src",
					"openEuler-24.03-LTS-SP1:activemq-5.19.9-1.oe2403sp1.noarch",
					"openEuler-24.03-LTS-SP1:activemq-javadoc-5.19.9-1.oe2403sp1.noarch"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP1:activemq-5.19.9-1.oe2403sp1.src",
						"openEuler-24.03-LTS-SP1:activemq-5.19.9-1.oe2403sp1.noarch",
						"openEuler-24.03-LTS-SP1:activemq-javadoc-5.19.9-1.oe2403sp1.noarch"
					],
					"details":"activemq security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3265"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":7.5,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP1:activemq-5.19.9-1.oe2403sp1.src",
						"openEuler-24.03-LTS-SP1:activemq-5.19.9-1.oe2403sp1.noarch",
						"openEuler-24.03-LTS-SP1:activemq-javadoc-5.19.9-1.oe2403sp1.noarch"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2026-59878"
		},
		{
			"cve":"CVE-2026-61487",
			"notes":[
				{
					"text":"Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.\n\n An authenticated low-privilege user can bypass a per-destination\nwrite ACL by sending to an ActiveMQ temporary composite destination whose physical name is a\ncomma-separated composite of real queues. This allows publishing messages to any of the destinations in the list without proper write ACL permissions because the authorization check is bypassed due to the composite destination being marked as temporary.\nThis issue affects Apache ActiveMQ Broker: before 5.19.9, from 6.0.0 before 6.2.8; Apache ActiveMQ All: before 5.19.9, from 6.0.0 before 6.2.8; Apache ActiveMQ: before 5.19.9, from 6.0.0 before 6.2.8.\n\nUsers are recommended to upgrade to version 5.19.9, 6.2.8 or 6.3.0, which fixes the issue.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP1:activemq-5.19.9-1.oe2403sp1.src",
					"openEuler-24.03-LTS-SP1:activemq-5.19.9-1.oe2403sp1.noarch",
					"openEuler-24.03-LTS-SP1:activemq-javadoc-5.19.9-1.oe2403sp1.noarch"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP1:activemq-5.19.9-1.oe2403sp1.src",
						"openEuler-24.03-LTS-SP1:activemq-5.19.9-1.oe2403sp1.noarch",
						"openEuler-24.03-LTS-SP1:activemq-javadoc-5.19.9-1.oe2403sp1.noarch"
					],
					"details":"activemq security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3265"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"MEDIUM",
						"baseScore":6.5,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP1:activemq-5.19.9-1.oe2403sp1.src",
						"openEuler-24.03-LTS-SP1:activemq-5.19.9-1.oe2403sp1.noarch",
						"openEuler-24.03-LTS-SP1:activemq-javadoc-5.19.9-1.oe2403sp1.noarch"
					]
				}
			],
			"threats":[
				{
					"details":"Medium",
					"category":"impact"
				}
			],
			"title":"CVE-2026-61487"
		}
	]
}