← Back

CVE-2026-41043

nvd nist
Published: Apr 24, 2026Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Exploitability: 3.9 / Impact: 2.5
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. An authenticated attacker can show malicious content when browsing queues in the web console by overriding the content type to be HTML (instead of XML) and by injecting HTML into a JMS selector field. This issue affects Apache ActiveMQ: before 5.19.6, from 6.0.0 before 6.2.5; Apache ActiveMQ Web: before 5.19.6, from 6.0.0 before 6.2.5. Users are recommended to upgrade to version 6.2.5 or 5.19.6, which fixes the issue.

Affected (4)

2 products
Activemq
Activemq Web
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Before 5.19.6
From 6.0.0 to 6.2.5
Apache
Before 5.19.6
From 6.0.0 to 6.2.5

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List

Timeline

No history available yet.