Directory Traversal Affecting apache-activemq-artemis package, versions <2.53.0-r5


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.42% (34th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CHAINGUARDLATEST-APACHEACTIVEMQARTEMIS-16119930
  • published22 Apr 2026
  • disclosed7 Apr 2026

Introduced: 7 Apr 2026

CVE-2026-33227  (opens in a new tab)
CWE-22  (opens in a new tab)

How to fix?

Upgrade Chainguard apache-activemq-artemis to version 2.53.0-r5 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream apache-activemq-artemis package and not the apache-activemq-artemis package as distributed by Chainguard. See How to fix? for Chainguard relevant fixed versions and status.

Improper validation and restriction of a classpath path name vulnerability in

Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ.

In two instances (when creating a Stomp consumer and also browsing messages in the Web console) an authenticated user provided "key" value could be constructed to traverse the classpath due to path concatenation. As a result, the application is exposed to a classpath path resource loading vulnerability that could potentially be chained together with another attack to lead to exploit.

This issue affects Apache ActiveMQ Client: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ Broker: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ All: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ Web: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ: before 5.19.3, from 6.0.0 before 6.2.2.

Users are recommended to upgrade to version 5.19.4 or 6.2.3, which fixes the issue. Note: 5.19.3 and 6.2.2 also fix this issue, but that is limited to non-Windows environments due to a path separator resolution bug fixed in 5.19.4 and 6.2.3.

CVSS Base Scores

version 3.1