CVE-2026-41043 Details
Description
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. An authenticated attacker can show malicious content when browsing queues in the web console by overriding the content type to be HTML (instead of XML) and by injecting HTML into a JMS selector field. This issue affects Apache ActiveMQ: before 5.19.6, from 6.0.0 before 6.2.5; Apache ActiveMQ Web: before 5.19.6, from 6.0.0 before 6.2.5. Users are recommended to upgrade to version 6.2.5 or 5.19.6, which fixes the issue.
A cross-site scripting (XSS) vulnerability has been identified in Apache ActiveMQ and Apache ActiveMQ Web. This issue allows authenticated attackers to inject malicious HTML content into a JMS selector field, which is then rendered in the web console. The vulnerability arises from improper handling of script-related HTML tags, enabling the injection of HTML when the content type is incorrectly set to HTML instead of XML. This issue affects Apache ActiveMQ versions prior to 5.19.6 and 6.0.0 versions prior to 6.2.5, as well as Apache ActiveMQ Web versions prior to 5.19.6 and 6.0.0 versions prior to 6.2.5.
Users are advised to upgrade to Apache ActiveMQ version 6.2.5 or 5.19.6, both of which address this vulnerability. For Apache ActiveMQ Web, the same version recommendations apply.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/04/23/5 | CVE | Mailing List |
| https://activemq.apache.org/security-advisories.data/CVE-2026-41043-announcement.txt | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
| CWE-915 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache activemq | < 5.19.6 >= 6.0.0, < 6.2.5 |
CPE
Remediation
| |
| apache activemq web | < 5.19.6 >= 6.0.0, < 6.2.5 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 27, 2026 | Initial Analysis | [email protected] |
| Apr 24, 2026 | CVE Modified | CISA-ADP |
| Apr 24, 2026 | New CVE Received | [email protected] |
| Apr 24, 2026 | CVE Modified | CVE |