All CosmicBytez Labs articles tagged #Message Broker, across news, security advisories, how-to guides, and projects.
A pre-auth flaw in Artemis cluster discovery lets network-adjacent attackers capture admin credentials during the connection handshake.
Attackers can craft a CORE protocol SESSION_REATTACH packet to steal an existing Artemis session and its authenticated privileges.
A crafted OpenWire RemoveSubscriptionInfo command lets unauthenticated attackers delete Artemis broker queues before login completes.
CVE-2026-34197, a remote code execution vulnerability in Apache ActiveMQ's Jolokia management API, is being actively exploited in the wild. CISA has added...
Security researchers discovered a remote code execution vulnerability in Apache ActiveMQ Classic that went undetected for 13 years, allowing attackers to...