Skip to content
Red HatCVE-2026-101292

Red Hat AMQ Broker 7: unsafe reflection

High8.2CVE-2026-101292 · Published Sep 28, 2026 · updated Sep 29, 2026

Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getFederationPolicy(). The method calls Class.forName(clazz).getConstructor().newInstance() where clazz is read directly from the CORE protocol wire buffer without type validation. An authenticated federation peer can send a FEDERATION_DOWNSTREAM_CONNECT packet with a crafted class name, causing the broker to load and instantiate arbitrary classes visible to the Artemis module classloader. Static initializers (<clinit>) and no-argument constructors (<init>()) execute as side effects before the type cast, enabling denial of service via system-property poisoning, out-of-memory conditions via classloading, or broker state manipulation.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat AMQ Broker 7
Product
all versionsNo fix yet
Red Hat JBoss Enterprise Application Platform 7
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat Enterprise Linux: denial of service
Low3.6Sep 28
Flatpak writes the OCI repository authentication token with world-readable...
Low3.2Sep 28
Red Hat Enterprise Linux: denial of service
Low3.9Sep 28
Red Hat Enterprise Linux: path traversal
High7.1Sep 28
Red Hat GCC.: use after free
High7.0Sep 28
A flaw was found in the StreamsHub Console for Apache Kafka
Medium6.5Sep 28

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.