Advisories · nist.gov

CVE-2026-49363

nist.gov

An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBE_TOPOLOGY request prior to authentication. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.

More from nist.gov

Also in Advisories

  1. Friday Squid Blogging: Rotting Squid on a Beached California BoatBruce Schneierschneier.com
  2. My Talk at DEF CONBruce Schneierschneier.com
  3. Cliff Stoll’s DEF CON TalkBruce Schneierschneier.com
  4. AIs Compress Exploit TimelineBruce Schneierschneier.com
  5. Revised Medical Criteria for Evaluating Cardiovascular Disordersfederalregister.gov
  6. Continuation of the National Emergency With Respect to Persons Who Commit, Threaten To Commit, or Support Terrorismfederalregister.gov