An authenticated client could attach a consumer with a selector containing crafted wildcard usage that results in excessive evaluation during message delivery attempts, occupying a shared broker thread and leading to denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes this issue.
History

Thu, 10 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache activemq Artemis
Apache artemis
Vendors & Products Apache
Apache activemq Artemis
Apache artemis

Thu, 10 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
References

Thu, 10 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Description An authenticated client could attach a consumer with a selector containing crafted wildcard usage that results in excessive evaluation during message delivery attempts, occupying a shared broker thread and leading to denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes this issue.
Title Apache Artemis, Apache ActiveMQ Artemis: Message selector wildcard handling could lead to denial of service
Weaknesses CWE-1333
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2026-09-10T04:36:08.059Z

Updated: 2026-09-10T05:12:01.308Z

Reserved: 2026-08-18T12:59:58.950Z

Link: CVE-2026-75880

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-10T05:17:01.673

Modified: 2026-09-10T06:17:05.790

Link: CVE-2026-75880

cve-icon Redhat

No data.