Red Hat Security Advisory: Red Hat AMQ Broker 7.13.6 release and security update
🔗 CVE IDs covered (59)
📋 Description
CVE-2026-9595 — webpack-dev-server: webpack-dev-server: Information disclosure and denial of service via improper proxy configuration
CVE-2026-10050 — jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision
CVE-2026-10051 — jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections
CVE-2026-12143 — form-data: form-data: Form field override via CRLF injection
CVE-2026-12151 — undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames
CVE-2026-13149 — brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity
CVE-2026-13676 — fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization
CVE-2026-34478 — org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames
CVE-2026-34480 — org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging
CVE-2026-34481 — org.apache.logging.log4j: Apache Log4j JsonTemplateLayout: Denial of Service via invalid JSON output
CVE-2026-40984 — micrometer-core: micrometer-jetty11: micrometer-jetty12: Micrometer: Denial of Service via specially crafted HTTP requests
CVE-2026-42198 — jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication
CVE-2026-42264 — axios: Axios: Prototype pollution allows information disclosure and request manipulation
CVE-2026-42338 — ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input
CVE-2026-42578 — netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation
CVE-2026-42581 — netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers
CVE-2026-42584 — netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion
CVE-2026-42587 — netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression
CVE-2026-42588 — org.apache.activemq/activemq-broker: org.apache.activemq/activemq-all: org.apache.activemq/apache-activemq: Apache ActiveMQ: Arbitrary code execution via improper input validation in Jolokia JMX-HTTP bridge
CVE-2026-44248 — netty: io.netty/netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 header
CVE-2026-44249 — netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation
CVE-2026-44486 — axios: Axios: Information disclosure of proxy credentials via HTTP redirects
CVE-2026-44487 — axios: Axios: Information disclosure of proxy credentials via redirect flows
CVE-2026-44488 — axios: Axios: Denial of Service due to unenforced request and response size limits
CVE-2026-44492 — axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization
CVE-2026-44494 — axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution
CVE-2026-44495 — axios: Axios: Information disclosure due to prototype pollution vulnerability
CVE-2026-44496 — axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name
CVE-2026-45205 — commons-configuration: Apache Commons Configuration: Denial of Service via uncontrolled recursion with crafted YAML input
CVE-2026-45416 — netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake
CVE-2026-45736 — ws: ws: Uninitialized memory disclosure via websocket.close() with TypedArray
CVE-2026-48779 — ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments
CVE-2026-49362 — artemis-server: undertow-core: wildfly-messaging-activemq-subsystem: artemis core protocol permits unauthed queue creation
CVE-2026-49363 — artemis-server: artemis-server: Pre-auth topology disclosure via CORE SUBSCRIBE_TOPOLOGY_V2 on channel0
CVE-2026-49364 — wildfly-messaging-activemq-subsystem: artemis-server: jgroups: artemis cluster password leak via jgroups spoof
CVE-2026-49432 — org.apache.activemq/activemq: org.apache.activemq/activemq-all: org.apache.activemq/activemq-stomp: Apache ActiveMQ: Denial of Service via improper input validation in STOMP connector
CVE-2026-49978 — dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution
CVE-2026-50010 — netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass
CVE-2026-50734 — Apache ActiveMQ Client: Apache ActiveMQ: Apache ActiveMQ All: Apache ActiveMQ: Denial of Service via crafted WireFormatInfo frame
CVE-2026-53916 — activemq-stomp: Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header buffer in STOMP NIO codec
CVE-2026-54512 — jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass
CVE-2026-54513 — jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
CVE-2026-55831 — io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing
CVE-2026-55833 — netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification
CVE-2026-56745 — netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec
CVE-2026-56746 — io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header
CVE-2026-57822 — artemis-core-client: activemq-artemis: Unsafe deserialization via JsonUtil CompositeData on management address
CVE-2026-57967 — artemis-server: Apache Artemis — session hijack via missing authentication
CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents
CVE-2026-59873 — tar: node-tar: Denial of Service via crafted gzip bomb
CVE-2026-59874 — tar: Node-tar: Denial of Service via malformed tar archive header
CVE-2026-59888 — com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records
CVE-2026-59899 — io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb)
CVE-2026-62243 — io.netty/netty-handler: Netty: TLS hostname verification bypass via OpenSSL client path misconfiguration
CVE-2026-66257 — qpid-proton-j: Apache Qpid Proton-J: Denial of Service via unbounded symbol value caching
CVE-2026-66273 — org.apache.qpid/proton-j: Apache Qpid Proton-J: Denial of Service due to excessive allocation
CVE-2026-66274 — org.apache.qpid/proton-j: Apache Qpid Proton-J: Denial of Service via unbounded type nesting
CVE-2026-67593 — artemis-openwire-protocol: AMQ Broker Artemis: pre-authentication arbitrary durable queue deletion via OpenWire RemoveSubscriptionInfo
CVE-2026-68494 — com.fasterxml.jackson.core/jackson-core: tools.jackson.core/jackson-core: jackson-core: Denial of Service via incomplete fix in async JSON parser
🎯 Affected products1
- Red Hat AMQ Broker 7.13.6
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings. The References section of this erratum contains a download link (you must log in to download the update). Workaround: To mitigate this issue, users should avoid configuring `webpack-dev-server` with a broad proxy context (e.g., `/`) when WebSocket forwarding (`ws: true`) is enabled. Instead, define specific paths for the proxy context. Alternatively, disable WebSocket forwarding by omitting `ws: true` from the proxy entry if WebSocket functionality is not required for the proxy target. This configuration change may require restarting the `webpack-dev-server` instance to take effect. Workaround: To mitigate this vulnerability, ensure that all user passwords configured for HTTP Digest authentication in affected Eclipse Jetty deployments exclusively use characters within the Latin-1 character set. This prevents the character encoding collision that leads to authentication bypass. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Applications using the `form-data` library should implement strict input validation and sanitization for all field names and filenames derived from untrusted sources. This prevents the injection of control characters (CR, LF, ") that could lead to header injection or form field overrides. Deployments that exclusively use fixed or trusted field names are not impacted. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: There is no practical mitigation for this vulnerability. The brace-expansion package is typically a transitive dependency pulled in via minimatch and glob, making it difficult to isolate. Users should upgrade to a fixed version of brace-expansion when one becomes available. Workaround: Applications utilizing Netty's HttpProxyHandler must ensure that any user-controlled input used to populate outbound headers is rigorously sanitized to prevent CRLF injection. If comprehensive input sanitization cannot be implemented, restricting network access to the application that uses the HttpProxyHandler can reduce the attack surface. Workaround: To mitigate this issue, configure any reverse proxies or load balancers in front of Netty to either reject HTTP/1.0 requests containing both Transfer-Encoding: chunked and Content-Length headers, or to explicitly prioritize the Transfer-Encoding header over Content-Length for HTTP/1.0 traffic. This ensures consistent interpretation of message boundaries and prevents request smuggling attacks. Workaround: To mitigate this issue, restrict Apache Commons Configuration to process only trusted YAML configuration files. Implement strict input validation for any YAML content originating from untrusted sources to prevent the parsing of malformed input with cyclical references. This operational control reduces the exposure to denial of service attacks. Workaround: To mitigate this issue, configure applications utilizing Netty's `SslClientHelloHandler` to specify a non-zero value for the `maxClientHelloLength` parameter. This will enable the internal length validation, preventing the eager allocation of large memory buffers when processing crafted TLS ClientHello messages. Refer to your specific application's documentation for details on configuring Netty's TLS handler. A restart of the affected application or service is required for the configuration changes to take effect. Workaround: 1. Remove Core protocol from internet-facing acceptors -- configure the protocols parameter to exclude Core protocol on any acceptor receiving untrusted connections. In EAP, the :8080 HTTP-upgrade acceptor supports Core by default; restricting to AMQP/STOMP/OpenWire prevents the attack entirely. 2. Enable mutual TLS -- configure sslEnabled=true with needClientAuth=true on all Core protocol acceptors. TLS handshake failure occurs before any protocol-level packet can be sent. 3. Disable HTTP-upgrade for Core protocol if not required -- remove the http-upgrade element from the Artemis acceptor configuration to eliminate the :8080 attack surface. Workaround: Upgrade to version 2.18.8, 2.21.4, or 3.1.4 or later to address this vulnerability. If upgrading is not immediately possible, remove BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() from the application’s ObjectMapper configuration to eliminate the affected deserialization path. Rebuild and restart the application to apply the configuration change. As an additional mitigation, disable polymorphic deserialization of untrusted data where possible by avoiding or removing default typing features such as activateDefaultTyping() or enableDefaultTyping(). When polymorphic deserialization is required, restrict allowed subtypes using a strict whitelist of trusted application packages and avoid broad or permissive type validation rules. Workaround: If CORS short-circuit functionality is not required, disable the shortCircuit() configuration in the CorsHandler. Alternatively, implement application-level origin validation to reject requests with null Origin headers. A web application firewall (WAF) can also be configured to block requests with null or missing Origin headers. Workaround: Restrict MANAGE role access: ensure only trusted administrative accounts have the manage permission on the activemq.management address. Review security-setting configurations in standalone-full.xml (EAP) or broker.xml (AMQ Broker) to confirm management address role assignments follow least-privilege principles. Additionally, restrict network access to messaging ports (default 61616) so that management operations are only accessible from administrative networks. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations. Workaround: This vulnerability only affects applications that explicitly configure Netty to use the OpenSSL TLS provider (SslProvider.OPENSSL). The following mitigations can reduce exposure without applying a patch: 1) Use the default JDK SSL provider — Do not configure SslProvider.OPENSSL in your Netty SslContext setup. The default JDK SSL provider (SslProvider.JDK) is not affected by this vulnerability. Most applications use the JDK default unless explicitly overridden. 2) Use X509ExtendedTrustManager — If the OpenSSL provider is required, ensure the configured trust manager extends X509ExtendedTrustManager rather than the plain X509TrustManager interface. The extended variant performs hostname verification independently of the Netty wrapping logic. 3) Run on Java 24 or earlier — The vulnerable code path only triggers on Java 25+ where sun.misc.Unsafe-based trust-manager wrapping is unavailable. Running on earlier Java versions (e.g., Java 21 LTS) means the wrapping works correctly and hostname verification stays enabled. Workaround: To mitigate this issue, restrict network access to services utilizing Apache Qpid Proton-J to trusted clients and networks only. Implement firewall rules to limit inbound connections to the specific ports used by these services. This operational control reduces the attack surface by preventing untrusted external access, but may impact legitimate client connectivity if not carefully configured. Workaround: 1. Remove OpenWire fr…
🔗 References (71)
- selfhttps://access.redhat.com/errata/RHSA-2026:66545
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/updates/classification#important
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=jboss.amq.broker&version=7.13.6
- externalhttps://docs.redhat.com/en/documentation/red_hat_amq_broker/7.13
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2457321
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2457323
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2457328
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2463857
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2467927
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2476810
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2477220
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2477224
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2477226
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2477231
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2477232
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2477425
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2477914
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2477945
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2478013
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2480638
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2486488
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2486716
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2487937
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2487938
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2487942
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2487943
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2487947
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2487948
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2487949
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2488081
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2488391
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2488429
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2488480
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2488934
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489661
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489980
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2492010
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2492015
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2492627
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2494197
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2494813
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2494841
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2494846
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2494847
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2495823
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2498116
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2498120
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2498122
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2499928
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2500096
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2500695
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2503101
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2503103
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2505422
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2505911
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2507482
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2510277
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2511026
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2511322
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2511326
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2511337
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2521309
- externalhttps://issues.redhat.com/browse/ENTMQBR-10728
- externalhttps://issues.redhat.com/browse/ENTMQBR-10729
- externalhttps://issues.redhat.com/browse/ENTMQBR-10877
- externalhttps://issues.redhat.com/browse/ENTMQBR-10913
- externalhttps://issues.redhat.com/browse/ENTMQBR-10916
- externalhttps://issues.redhat.com/browse/ENTMQBR-10983
- externalhttps://issues.redhat.com/browse/ENTMQBR-10989
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_66545.json