CVE WATCH / VULNERABILITY DETAIL

CVE-2026-101292

HIGHCVSS 8.2NVD feed

Published 28 September 2026 · tracked since 28 September 2026

Description

Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getFederationPolicy(). The method calls Class.forName(clazz).getConstructor().newInstance() where clazz is read directly from the CORE protocol wire buffer without type validation. An

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-101292 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-101292

HIGHCVSS 8.2NVD feed

Published 28 September 2026 · tracked since 28 September 2026

Description

Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getFederationPolicy(). The method calls Class.forName(clazz).getConstructor().newInstance() where clazz is read directly from the CORE protocol wire buffer without type validation. An

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]