- Issued:
- 2026-09-10
- Updated:
- 2026-09-10
RHSA-2026:66545 - Important: Red Hat AMQ Broker 7.13.6 release and security update
Synopsis
Important: Red Hat AMQ Broker 7.13.6 release and security update
Type/Severity
Security Advisory: Important
Topic
Red Hat AMQ Broker 7.13.6 is now available from the Red Hat Customer Portal.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Description
AMQ Broker is a high-performance messaging implementation based on ActiveMQ Artemis. It uses an asynchronous journal for fast message persistence, and supports multiple languages, protocols, and platforms.
This release of Red Hat AMQ Broker 7.13.6 includes security and bug fixes, and enhancements. For further information, refer to the release notes linked to in the References section.
Security Fix(es):
- (CVE-2026-10050) jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision
- (CVE-2026-12143) form-data: form-data: Form field override via CRLF injection
- (CVE-2026-12151) undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames
- (CVE-2026-13149) brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity
- (CVE-2026-13676) fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization
- (CVE-2026-40984) micrometer-core: Micrometer: Denial of Service via specially crafted HTTP requests
- (CVE-2026-42198) postgresql: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication
- (CVE-2026-42264) axios: Axios: Prototype pollution allows information disclosure and request manipulation
- (CVE-2026-42338) ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input
- (CVE-2026-42578) netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation
- (CVE-2026-42581) netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers
- (CVE-2026-42584) netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion
- (CVE-2026-42587) netty-codec-http: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression
- (CVE-2026-42588) activemq-broker: Apache ActiveMQ: Arbitrary code execution via improper input validation in Jolokia JMX-HTTP bridge
- (CVE-2026-44248) netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 header
- (CVE-2026-44249) netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation
- (CVE-2026-44486) axios: Axios: Information disclosure of proxy credentials via HTTP redirects
- (CVE-2026-44487) axios: Axios: Information disclosure of proxy credentials via redirect flows
- (CVE-2026-44488) axios: Axios: Denial of Service due to unenforced request and response size limits
- (CVE-2026-44492) axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization
- (CVE-2026-44494) axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution
- (CVE-2026-44495) axios: Axios: Information disclosure due to prototype pollution vulnerability
- (CVE-2026-44496) axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name
- (CVE-2026-45205) commons-configuration2: Apache Commons Configuration: Denial of Service via uncontrolled recursion with crafted YAML input
- (CVE-2026-45416) netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake
- (CVE-2026-45736) ws: ws: Uninitialized memory disclosure via
websocket.close()withTypedArray - (CVE-2026-48779) ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments
- (CVE-2026-49362) artemis-server: artemis core protocol permits unauthed queue creation
- (CVE-2026-49364) artemis-server: artemis cluster password leak via jgroups spoof
- (CVE-2026-49432) artemis-stomp-protocol: Apache ActiveMQ: Denial of Service via improper input validation in STOMP connector
- (CVE-2026-49978) dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution
- (CVE-2026-50010) netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass
- (CVE-2026-50734) activemq-client: Apache ActiveMQ: Denial of Service via crafted WireFormatInfo frame
- (CVE-2026-53916) artemis-stomp-protocol: Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header buffer in STOMP NIO codec
- (CVE-2026-54512) jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass
- (CVE-2026-54513) jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
- (CVE-2026-55831) netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing
- (CVE-2026-55833) netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification
- (CVE-2026-56745) netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec
- (CVE-2026-56746) netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header
- (CVE-2026-57967) artemis-server: Apache Artemis — session hijack via missing authentication
- (CVE-2026-59869) js-yaml: js-yaml: Denial of Service via crafted YAML documents
- (CVE-2026-59873) tar: node-tar: Denial of Service via crafted gzip bomb
- (CVE-2026-59874) tar: Node-tar: Denial of Service via malformed tar archive header
- (CVE-2026-59899) netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb)
- (CVE-2026-62243) netty-handler: Netty: TLS hostname verification bypass via OpenSSL client path misconfiguration
- (CVE-2026-66257) proton-j: Apache Qpid Proton-J: Denial of Service via unbounded symbol value caching
- (CVE-2026-66273) proton-j: Apache Qpid Proton-J: Denial of Service due to excessive allocation
- (CVE-2026-66274) amq-broker-maven-repository.zip: Apache Qpid Proton-J: Denial of Service via unbounded type nesting
- (CVE-2026-66274) amq-broker-bin.zip: Apache Qpid Proton-J: Denial of Service via unbounded type nesting
- (CVE-2026-67593) artemis-openwire-protocol: AMQ Broker Artemis: pre-authentication arbitrary durable queue deletion via OpenWire RemoveSubscriptionInfo
- (CVE-2026-68494) amq-broker-maven-repository.zip: jackson-core: Denial of Service via incomplete fix in async JSON parser
- (CVE-2026-68494) amq-broker-bin.zip: jackson-core: Denial of Service via incomplete fix in async JSON parser
- (CVE-2026-9595) webpack-dev-server: webpack-dev-server: Information disclosure and denial of service via improper proxy configuration
- (CVE-2026-10051) jetty-server: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections
- (CVE-2026-34478) log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames
- (CVE-2026-34480) log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging
- (CVE-2026-34481) log4j-layout-template-json: Apache Log4j JsonTemplateLayout: Denial of Service via invalid JSON output
- (CVE-2026-49363) artemis-server: artemis-server: Pre-auth topology disclosure via CORE SUBSCRIBE_TOPOLOGY_V2 on channel0
- (CVE-2026-57822) artemis-core-client: activemq-artemis: Unsafe deserialization via JsonUtil CompositeData on management address
- (CVE-2026-59888) jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records
For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Solution
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings.
The References section of this erratum contains a download link (you must log in to download the update).
Affected Products
| Product | Version | Arch |
|---|---|---|
| Red Hat JBoss Middleware | Text-Only Advisories | x86_64 |
Fixes
- This content is not included.BZ - 2457321
- This content is not included.BZ - 2457323
- This content is not included.BZ - 2457328
- This content is not included.BZ - 2463857
- This content is not included.BZ - 2467927
- This content is not included.BZ - 2476810
- This content is not included.BZ - 2477220
- This content is not included.BZ - 2477224
- This content is not included.BZ - 2477226
- This content is not included.BZ - 2477231
- This content is not included.BZ - 2477232
- This content is not included.BZ - 2477425
- This content is not included.BZ - 2477914
- This content is not included.BZ - 2477945
- This content is not included.BZ - 2478013
- This content is not included.BZ - 2480638
- This content is not included.BZ - 2486488
- This content is not included.BZ - 2486716
- This content is not included.BZ - 2487937
- This content is not included.BZ - 2487938
- This content is not included.BZ - 2487942
- This content is not included.BZ - 2487943
- This content is not included.BZ - 2487947
- This content is not included.BZ - 2487948
- This content is not included.BZ - 2487949
- This content is not included.BZ - 2488081
- This content is not included.BZ - 2488391
- This content is not included.BZ - 2488429
- This content is not included.BZ - 2488480
- This content is not included.BZ - 2488934
- This content is not included.BZ - 2489661
- This content is not included.BZ - 2489980
- This content is not included.BZ - 2492010
- This content is not included.BZ - 2492015
- This content is not included.BZ - 2492627
- This content is not included.BZ - 2494197
- This content is not included.BZ - 2494813
- This content is not included.BZ - 2494841
- This content is not included.BZ - 2494846
- This content is not included.BZ - 2494847
- This content is not included.BZ - 2495823
- This content is not included.BZ - 2498116
- This content is not included.BZ - 2498120
- This content is not included.BZ - 2498122
- This content is not included.BZ - 2499928
- This content is not included.BZ - 2500096
- This content is not included.BZ - 2500695
- This content is not included.BZ - 2503101
- This content is not included.BZ - 2503103
- This content is not included.BZ - 2505422
- This content is not included.BZ - 2505911
- This content is not included.BZ - 2507482
- This content is not included.BZ - 2510277
- This content is not included.BZ - 2511026
- This content is not included.BZ - 2511322
- This content is not included.BZ - 2511326
- This content is not included.BZ - 2511337
- This content is not included.BZ - 2521309
- This content is not included.ENTMQBR-10916
- This content is not included.ENTMQBR-10913
- This content is not included.ENTMQBR-10877
- This content is not included.ENTMQBR-10728
- This content is not included.ENTMQBR-10729
- This content is not included.ENTMQBR-10989
- This content is not included.ENTMQBR-10983
CVEs
- This content is not included.CVE-2026-9595
- This content is not included.CVE-2026-10050
- This content is not included.CVE-2026-10051
- This content is not included.CVE-2026-12143
- This content is not included.CVE-2026-12151
- This content is not included.CVE-2026-13149
- This content is not included.CVE-2026-13676
- CVE-2026-34478
- CVE-2026-34480
- CVE-2026-34481
- This content is not included.CVE-2026-40984
- This content is not included.CVE-2026-42198
- This content is not included.CVE-2026-42264
- This content is not included.CVE-2026-42338
- This content is not included.CVE-2026-42578
- This content is not included.CVE-2026-42581
- This content is not included.CVE-2026-42584
- This content is not included.CVE-2026-42587
- CVE-2026-42588
- CVE-2026-44248
- This content is not included.CVE-2026-44249
- CVE-2026-44486
- CVE-2026-44487
- CVE-2026-44488
- CVE-2026-44492
- CVE-2026-44494
- CVE-2026-44495
- This content is not included.CVE-2026-44496
- CVE-2026-45205
- This content is not included.CVE-2026-45416
- CVE-2026-45736
- CVE-2026-48779
- CVE-2026-49362
- CVE-2026-49363
- CVE-2026-49364
- CVE-2026-49432
- This content is not included.CVE-2026-49978
- This content is not included.CVE-2026-50010
- CVE-2026-50734
- CVE-2026-53916
- This content is not included.CVE-2026-54512
- This content is not included.CVE-2026-54513
- This content is not included.CVE-2026-55831
- This content is not included.CVE-2026-55833
- This content is not included.CVE-2026-56745
- This content is not included.CVE-2026-56746
- CVE-2026-57822
- CVE-2026-57967
- This content is not included.CVE-2026-59869
- This content is not included.CVE-2026-59873
- This content is not included.CVE-2026-59874
- This content is not included.CVE-2026-59888
- This content is not included.CVE-2026-59899
- This content is not included.CVE-2026-62243
- This content is not included.CVE-2026-66257
- This content is not included.CVE-2026-66273
- This content is not included.CVE-2026-66274
- CVE-2026-67593
- This content is not included.CVE-2026-68494
References
- https://access.redhat.com/security/updates/classification/#important
- https://access.redhat.com/security/updates/classification#important
- This content is not included.This content is not included.https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=jboss.amq.broker&version=7.13.6
- https://docs.redhat.com/en/documentation/red_hat_amq_broker/7.13
Additional information
- The Red Hat security contact is This content is not included.secalert@redhat.com. More contact details at Security Contacts and Procedures.
- Offline Security Data data is available for integration with other systems. See Offline Security Data API to get started.