Fedora Account System
Red Hat Associate
Red Hat Customer
Upstream report: CVE-2026-57822 reserved by Apache Security. Reporter: Clebert Suconic (Apache Artemis committer) via PSIRTSUPT-18814. Vulnerable class: org.apache.activemq.artemis.api.core.JsonUtil.fromJsonArray() Vulnerable JAR: artemis-core-client Affected versions: Artemis 2.16.0 through main (unfixed) Attack requires MANAGE role (high-privilege administrative permission). Impact: DoS only (deserialization bomb). No RCE or data exfiltration. Allowlist (java.util,java.lang,javax.management) blocks URLDNS and all known RCE gadget chains. Fix: Upstream plans to disallow JsonUtil from performing server-side deserialization. JsonUtil was only intended for client-side management console browsing. Cross-reference: This is the same issue as IBM EAP report Medium Finding jboss-eap_38.md.