GHSA-rf99-f9j2-gv3f
MODERATECVE-2026-40914A vulnerability exists in Apache Artemis whereby an application using the STOMP protocol with security credentials that grant either the consume or send permission on an address can augment the routing-type supported by that address even if said user doesn't have the createAddress permission for that particular address. A user could successfully send a message to an address or consume a message fr
- Affected
- >= 2.50.0, <= 2.53.0
- Fixed in
- 2.54.0
- Weakness
- CWE-863
- Published
- 2026-05-28
- Source
- github