CVE-2026-101292: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') in Red Hat Red Hat AMQ Broker 7
Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getFederationPolicy(). The method calls Class.forName(clazz).getConstructor().newInstance() where clazz is read directly from the CORE protocol wire buffer without type validation. An authenticated federation peer can send a FEDERATION_DOWNSTREAM_CONNECT packet with a crafted class name, causing the broker to load and instantiate arbitrary classes visible to the Artemis module classloader. Static initializers (<clinit>) and no-argument constructors (<init>()) execute as side effects before the type cast, enabling denial of service via system-property poisoning, out-of-memory conditions via classloading, or broker state manipulation.
AI Analysis
Technical Summary
Apache ActiveMQ Artemis versions prior to 2.34.0 contain an unsafe reflection vulnerability in the FederationStreamConnectMessage.getFederationPolicy() method. This method calls Class.forName(clazz).getConstructor().newInstance() where the class name (clazz) is read directly from the CORE protocol wire buffer without validation. An authenticated federation peer can exploit this by sending a crafted FEDERATION_DOWNSTREAM_CONNECT packet with a malicious class name, causing the broker to load and instantiate arbitrary classes visible to the Artemis module classloader. The execution of static initializers and no-argument constructors before type casting can result in denial of service via system-property poisoning, out-of-memory conditions, or manipulation of broker state.
Potential Impact
The vulnerability allows an authenticated federation peer to cause denial of service on the broker by triggering arbitrary class loading and instantiation. This can lead to system instability through system-property poisoning, excessive memory consumption, or manipulation of the broker's internal state. There is no indication of confidentiality impact, but integrity is affected due to possible broker state manipulation. The CVSS 3.1 score is 8.2 (High), reflecting network attack vector, low attack complexity, no privileges required, no user interaction, unchanged scope, no confidentiality impact, limited integrity impact, and high availability impact.
Mitigation Recommendations
A security update is available that fixes this vulnerability in Apache ActiveMQ Artemis version 2.34.0 and later. Users of Red Hat AMQ Broker 7 should upgrade to version 2.34.0 or later to remediate this issue. Patch status is confirmed by the Red Hat advisory. No additional mitigations are indicated or required beyond applying the official fix.
CVE-2026-101292: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') in Red Hat Red Hat AMQ Broker 7
Description
Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getFederationPolicy(). The method calls Class.forName(clazz).getConstructor().newInstance() where clazz is read directly from the CORE protocol wire buffer without type validation. An authenticated federation peer can send a FEDERATION_DOWNSTREAM_CONNECT packet with a crafted class name, causing the broker to load and instantiate arbitrary classes visible to the Artemis module classloader. Static initializers (<clinit>) and no-argument constructors (<init>()) execute as side effects before the type cast, enabling denial of service via system-property poisoning, out-of-memory conditions via classloading, or broker state manipulation.
CVSS v3.1
Score 8.2high
Affected software
Red Hat
Red Hat AMQ Broker 7
Red Hat
Red Hat JBoss Enterprise Application Platform 7
pkg:maven/org.apache.activemq/artemis-core-clientRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Apache ActiveMQ Artemis versions prior to 2.34.0 contain an unsafe reflection vulnerability in the FederationStreamConnectMessage.getFederationPolicy() method. This method calls Class.forName(clazz).getConstructor().newInstance() where the class name (clazz) is read directly from the CORE protocol wire buffer without validation. An authenticated federation peer can exploit this by sending a crafted FEDERATION_DOWNSTREAM_CONNECT packet with a malicious class name, causing the broker to load and instantiate arbitrary classes visible to the Artemis module classloader. The execution of static initializers and no-argument constructors before type casting can result in denial of service via system-property poisoning, out-of-memory conditions, or manipulation of broker state.
Potential Impact
The vulnerability allows an authenticated federation peer to cause denial of service on the broker by triggering arbitrary class loading and instantiation. This can lead to system instability through system-property poisoning, excessive memory consumption, or manipulation of the broker's internal state. There is no indication of confidentiality impact, but integrity is affected due to possible broker state manipulation. The CVSS 3.1 score is 8.2 (High), reflecting network attack vector, low attack complexity, no privileges required, no user interaction, unchanged scope, no confidentiality impact, limited integrity impact, and high availability impact.
Mitigation Recommendations
A security update is available that fixes this vulnerability in Apache ActiveMQ Artemis version 2.34.0 and later. Users of Red Hat AMQ Broker 7 should upgrade to version 2.34.0 or later to remediate this issue. Patch status is confirmed by the Red Hat advisory. No additional mitigations are indicated or required beyond applying the official fix.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-09-28T12:37:20.491Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/errata/RHSA-2026:53644","vendor":"Red Hat"},{"url":"https://access.redhat.com/security/cve/CVE-2026-101292","vendor":"Red Hat"}]
Threat ID: 6aba65c2f7a7c54106b1d6b1
Added to database: 09/28/2026, 13:04:02 UTC
Last enriched: 09/28/2026, 13:17:57 UTC
Last updated: 09/29/2026, 01:57:23 UTC
Views: 16
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.