Fedora Account System
Red Hat Associate
Red Hat Customer
Source: Internal security audit — AMQ Broker f005 Upstream project: Apache ActiveMQ Artemis Upstream advisory: None — pending report to security Affected code: - OpenWireConnection.java — processRemoveSubscription() executes pre-auth, calls server.destroyQueue(SimpleString) with null SecurityAuth, skipping authorization check entirely Fix status: No upstream fix available. Vulnerability confirmed in upstream versions 2.33.0, 2.40.0, 2.55.0 (latest) and downstream AMQ Broker 7.14 GA.
This issue has been addressed in the following products: Red Hat AMQ Broker 7.14.1 Via RHSA-2026:66488 https://access.redhat.com/errata/RHSA-2026:66488
This issue has been addressed in the following products: Red Hat AMQ Broker 7.13.6 Via RHSA-2026:66545 https://access.redhat.com/errata/RHSA-2026:66545