Apache ActiveMQ Web (5.19.7/6.2.6) XSS via MessageServlet header injection
CVE-2026-42253 Published on June 1, 2026
Apache ActiveMQ, Apache ActiveMQ Web: HTTP Response Header Injection via JMS Message Properties
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web.
The MessageServlet in the ActiveMQ web console API copies every JMS message
property into an HTTP response header without any validation. This can allow overwriting and injecting security headers by setting them on JMS messages that are returned by the servlet.
This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ Web: before 5.19.7, from 6.0.0 before 6.2.6.
Users are recommended to upgrade to version 5.19.7 or 6.2.6, which fixes the issue. The MessageServlet has now been deprecated and disabled by default.
Weakness Type
What is a XSS Vulnerability?
The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVE-2026-42253 has been classified to as a XSS vulnerability or weakness.
Products Associated with CVE-2026-42253
Want to know whenever a new CVE is published for Apache ActiveMQ? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache ActiveMQ:- Before 5.19.7 is affected.
- Version 6.0.0 and below 6.2.6 is affected.
- Before 5.19.7 is affected.
- Version 6.0.0 and below 6.2.6 is affected.