RHSA-2026:66545HighCVSS 9.1

Red Hat Security Advisory: Red Hat AMQ Broker 7.13.6 release and security update

Published
September 10, 2026
Last Modified
September 11, 2026

🔗 CVE IDs covered (59)

📋 Description

CVE-2026-9595 — webpack-dev-server: webpack-dev-server: Information disclosure and denial of service via improper proxy configuration CVE-2026-10050 — jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision CVE-2026-10051 — jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections CVE-2026-12143 — form-data: form-data: Form field override via CRLF injection CVE-2026-12151 — undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames CVE-2026-13149 — brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity CVE-2026-13676 — fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization CVE-2026-34478 — org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames CVE-2026-34480 — org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging CVE-2026-34481 — org.apache.logging.log4j: Apache Log4j JsonTemplateLayout: Denial of Service via invalid JSON output CVE-2026-40984 — micrometer-core: micrometer-jetty11: micrometer-jetty12: Micrometer: Denial of Service via specially crafted HTTP requests CVE-2026-42198 — jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication CVE-2026-42264 — axios: Axios: Prototype pollution allows information disclosure and request manipulation CVE-2026-42338 — ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input CVE-2026-42578 — netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation CVE-2026-42581 — netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers CVE-2026-42584 — netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion CVE-2026-42587 — netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression CVE-2026-42588 — org.apache.activemq/activemq-broker: org.apache.activemq/activemq-all: org.apache.activemq/apache-activemq: Apache ActiveMQ: Arbitrary code execution via improper input validation in Jolokia JMX-HTTP bridge CVE-2026-44248 — netty: io.netty/netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 header CVE-2026-44249 — netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation CVE-2026-44486 — axios: Axios: Information disclosure of proxy credentials via HTTP redirects CVE-2026-44487 — axios: Axios: Information disclosure of proxy credentials via redirect flows CVE-2026-44488 — axios: Axios: Denial of Service due to unenforced request and response size limits CVE-2026-44492 — axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization CVE-2026-44494 — axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution CVE-2026-44495 — axios: Axios: Information disclosure due to prototype pollution vulnerability CVE-2026-44496 — axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name CVE-2026-45205 — commons-configuration: Apache Commons Configuration: Denial of Service via uncontrolled recursion with crafted YAML input CVE-2026-45416 — netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake CVE-2026-45736 — ws: ws: Uninitialized memory disclosure via websocket.close() with TypedArray CVE-2026-48779 — ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments CVE-2026-49362 — artemis-server: undertow-core: wildfly-messaging-activemq-subsystem: artemis core protocol permits unauthed queue creation CVE-2026-49363 — artemis-server: artemis-server: Pre-auth topology disclosure via CORE SUBSCRIBE_TOPOLOGY_V2 on channel0 CVE-2026-49364 — wildfly-messaging-activemq-subsystem: artemis-server: jgroups: artemis cluster password leak via jgroups spoof CVE-2026-49432 — org.apache.activemq/activemq: org.apache.activemq/activemq-all: org.apache.activemq/activemq-stomp: Apache ActiveMQ: Denial of Service via improper input validation in STOMP connector CVE-2026-49978 — dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution CVE-2026-50010 — netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass CVE-2026-50734 — Apache ActiveMQ Client: Apache ActiveMQ: Apache ActiveMQ All: Apache ActiveMQ: Denial of Service via crafted WireFormatInfo frame CVE-2026-53916 — activemq-stomp: Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header buffer in STOMP NIO codec CVE-2026-54512 — jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass CVE-2026-54513 — jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution CVE-2026-55831 — io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing CVE-2026-55833 — netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification CVE-2026-56745 — netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec CVE-2026-56746 — io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header CVE-2026-57822 — artemis-core-client: activemq-artemis: Unsafe deserialization via JsonUtil CompositeData on management address CVE-2026-57967 — artemis-server: Apache Artemis — session hijack via missing authentication CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents CVE-2026-59873 — tar: node-tar: Denial of Service via crafted gzip bomb CVE-2026-59874 — tar: Node-tar: Denial of Service via malformed tar archive header CVE-2026-59888 — com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records CVE-2026-59899 — io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) CVE-2026-62243 — io.netty/netty-handler: Netty: TLS hostname verification bypass via OpenSSL client path misconfiguration CVE-2026-66257 — qpid-proton-j: Apache Qpid Proton-J: Denial of Service via unbounded symbol value caching CVE-2026-66273 — org.apache.qpid/proton-j: Apache Qpid Proton-J: Denial of Service due to excessive allocation CVE-2026-66274 — org.apache.qpid/proton-j: Apache Qpid Proton-J: Denial of Service via unbounded type nesting CVE-2026-67593 — artemis-openwire-protocol: AMQ Broker Artemis: pre-authentication arbitrary durable queue deletion via OpenWire RemoveSubscriptionInfo CVE-2026-68494 — com.fasterxml.jackson.core/jackson-core: tools.jackson.core/jackson-core: jackson-core: Denial of Service via incomplete fix in async JSON parser

🎯 Affected products1

  • Red Hat AMQ Broker 7.13.6

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings. The References section of this erratum contains a download link (you must log in to download the update). Workaround: To mitigate this issue, users should avoid configuring `webpack-dev-server` with a broad proxy context (e.g., `/`) when WebSocket forwarding (`ws: true`) is enabled. Instead, define specific paths for the proxy context. Alternatively, disable WebSocket forwarding by omitting `ws: true` from the proxy entry if WebSocket functionality is not required for the proxy target. This configuration change may require restarting the `webpack-dev-server` instance to take effect. Workaround: To mitigate this vulnerability, ensure that all user passwords configured for HTTP Digest authentication in affected Eclipse Jetty deployments exclusively use characters within the Latin-1 character set. This prevents the character encoding collision that leads to authentication bypass. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Applications using the `form-data` library should implement strict input validation and sanitization for all field names and filenames derived from untrusted sources. This prevents the injection of control characters (CR, LF, ") that could lead to header injection or form field overrides. Deployments that exclusively use fixed or trusted field names are not impacted. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: There is no practical mitigation for this vulnerability. The brace-expansion package is typically a transitive dependency pulled in via minimatch and glob, making it difficult to isolate. Users should upgrade to a fixed version of brace-expansion when one becomes available. Workaround: Applications utilizing Netty's HttpProxyHandler must ensure that any user-controlled input used to populate outbound headers is rigorously sanitized to prevent CRLF injection. If comprehensive input sanitization cannot be implemented, restricting network access to the application that uses the HttpProxyHandler can reduce the attack surface. Workaround: To mitigate this issue, configure any reverse proxies or load balancers in front of Netty to either reject HTTP/1.0 requests containing both Transfer-Encoding: chunked and Content-Length headers, or to explicitly prioritize the Transfer-Encoding header over Content-Length for HTTP/1.0 traffic. This ensures consistent interpretation of message boundaries and prevents request smuggling attacks. Workaround: To mitigate this issue, restrict Apache Commons Configuration to process only trusted YAML configuration files. Implement strict input validation for any YAML content originating from untrusted sources to prevent the parsing of malformed input with cyclical references. This operational control reduces the exposure to denial of service attacks. Workaround: To mitigate this issue, configure applications utilizing Netty's `SslClientHelloHandler` to specify a non-zero value for the `maxClientHelloLength` parameter. This will enable the internal length validation, preventing the eager allocation of large memory buffers when processing crafted TLS ClientHello messages. Refer to your specific application's documentation for details on configuring Netty's TLS handler. A restart of the affected application or service is required for the configuration changes to take effect. Workaround: 1. Remove Core protocol from internet-facing acceptors -- configure the protocols parameter to exclude Core protocol on any acceptor receiving untrusted connections. In EAP, the :8080 HTTP-upgrade acceptor supports Core by default; restricting to AMQP/STOMP/OpenWire prevents the attack entirely. 2. Enable mutual TLS -- configure sslEnabled=true with needClientAuth=true on all Core protocol acceptors. TLS handshake failure occurs before any protocol-level packet can be sent. 3. Disable HTTP-upgrade for Core protocol if not required -- remove the http-upgrade element from the Artemis acceptor configuration to eliminate the :8080 attack surface. Workaround: Upgrade to version 2.18.8, 2.21.4, or 3.1.4 or later to address this vulnerability. If upgrading is not immediately possible, remove BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() from the application’s ObjectMapper configuration to eliminate the affected deserialization path. Rebuild and restart the application to apply the configuration change. As an additional mitigation, disable polymorphic deserialization of untrusted data where possible by avoiding or removing default typing features such as activateDefaultTyping() or enableDefaultTyping(). When polymorphic deserialization is required, restrict allowed subtypes using a strict whitelist of trusted application packages and avoid broad or permissive type validation rules. Workaround: If CORS short-circuit functionality is not required, disable the shortCircuit() configuration in the CorsHandler. Alternatively, implement application-level origin validation to reject requests with null Origin headers. A web application firewall (WAF) can also be configured to block requests with null or missing Origin headers. Workaround: Restrict MANAGE role access: ensure only trusted administrative accounts have the manage permission on the activemq.management address. Review security-setting configurations in standalone-full.xml (EAP) or broker.xml (AMQ Broker) to confirm management address role assignments follow least-privilege principles. Additionally, restrict network access to messaging ports (default 61616) so that management operations are only accessible from administrative networks. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations. Workaround: This vulnerability only affects applications that explicitly configure Netty to use the OpenSSL TLS provider (SslProvider.OPENSSL). The following mitigations can reduce exposure without applying a patch: 1) Use the default JDK SSL provider — Do not configure SslProvider.OPENSSL in your Netty SslContext setup. The default JDK SSL provider (SslProvider.JDK) is not affected by this vulnerability. Most applications use the JDK default unless explicitly overridden. 2) Use X509ExtendedTrustManager — If the OpenSSL provider is required, ensure the configured trust manager extends X509ExtendedTrustManager rather than the plain X509TrustManager interface. The extended variant performs hostname verification independently of the Netty wrapping logic. 3) Run on Java 24 or earlier — The vulnerable code path only triggers on Java 25+ where sun.misc.Unsafe-based trust-manager wrapping is unavailable. Running on earlier Java versions (e.g., Java 21 LTS) means the wrapping works correctly and hostname verification stays enabled. Workaround: To mitigate this issue, restrict network access to services utilizing Apache Qpid Proton-J to trusted clients and networks only. Implement firewall rules to limit inbound connections to the specific ports used by these services. This operational control reduces the attack surface by preventing untrusted external access, but may impact legitimate client connectivity if not carefully configured. Workaround: 1. Remove OpenWire fr…

🔗 References (71)