CyberzSOC

Applicability
← Back to CVE-2026-34197

CVE-2026-34197

CVSS 8.8 In CISA KEV Apache

Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.

Does it affect your version?

A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.

What each source says

Red Hat CSAF/VEX
precedence 100 · revised 2026-08-17
14 not affected
OSV.dev (incl. GHSA)
precedence 80 · revised 2026-09-10
8 affected 8 fixed
CVE List v5 (CNA container)
precedence 60 · revised 2026-08-17
6 affected
CVE List v5 (ADP/Vulnrichment)
precedence 55 · revised 2026-08-17
1 affected 8 not affected

Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.

Where sources disagree (2)

pkg:maven/org.apache.activemq/activemq-broker 2 sources linked identifier
csaf_redhat:not_affected/not_applicable | osv:affected/vendor_fix | osv:fixed/vendor_fix
pkg:maven/org.apache.activemq/activemq-all 2 sources linked identifier
csaf_redhat:not_affected/not_applicable | osv:affected/vendor_fix | osv:fixed/vendor_fix

Each line is one product that two or more sources describe differently. Same identifier means they both named it the same way; linked identifier means they named it differently and meet at a package URL or CPE both assert. This is recorded rather than resolved: a vendor saying "not affected" where an ecosystem says "affected" is a fact about the disclosure, and flattening it would hide the more useful half.

Statements (45)

Product Status Versions Remediation Source
red_hat_fuse_7:activemq-all activemq-all as a component of Red Hat Fuse 7 not affected vulnerable code not present no version stated vendor label: activemq-all not applicable csaf_redhat
red_hat_amq_broker_7:activemq-broker activemq-broker as a component of Red Hat AMQ Broker 7 not affected vulnerable code not in execute path no version stated vendor label: activemq-broker not applicable csaf_redhat
red_hat_data_grid_8:activemq-broker activemq-broker as a component of Red Hat Data Grid 8 not affected component not present no version stated vendor label: activemq-broker not applicable csaf_redhat
red_hat_fuse_7:activemq-broker activemq-broker as a component of Red Hat Fuse 7 not affected vulnerable code not present no version stated vendor label: activemq-broker not applicable csaf_redhat
red_hat_jboss_enterprise_application_platform_7:activemq-broker activemq-broker as a component of Red Hat JBoss Enterprise Application Platform 7 not affected vulnerable code not present no version stated vendor label: activemq-broker not applicable csaf_redhat
red_hat_jboss_enterprise_application_platform_8:activemq-broker activemq-broker as a component of Red Hat JBoss Enterprise Application Platform 8 not affected vulnerable code not present no version stated vendor label: activemq-broker not applicable csaf_redhat
red_hat_jboss_enterprise_application_platform_expansion_pack:activemq-broker activemq-broker as a component of Red Hat JBoss Enterprise Application Platform Expansion Pack not affected vulnerable code not present no version stated vendor label: activemq-broker not applicable csaf_redhat
red_hat_enterprise_linux_8:log4j log4j as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: log4j not applicable csaf_redhat
red_hat_enterprise_linux_8:log4j-jcl log4j-jcl as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: log4j-jcl not applicable csaf_redhat
red_hat_enterprise_linux_9:log4j-jcl log4j-jcl as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: log4j-jcl not applicable csaf_redhat
red_hat_enterprise_linux_8:log4j-slf4j log4j-slf4j as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: log4j-slf4j not applicable csaf_redhat
red_hat_enterprise_linux_9:log4j-slf4j log4j-slf4j as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: log4j-slf4j not applicable csaf_redhat
red_hat_enterprise_linux_8:log4j-web log4j-web as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: log4j-web not applicable csaf_redhat
red_hat_enterprise_linux_9:log4j.src log4j.src as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: log4j.src not applicable csaf_redhat
activemq affected < 5.19.4 vendor fix → 5.19.4 osv BIT-activemq-2026-34197
activemq affected >= 6.0.0, < 6.2.3 vendor fix → 6.2.3 osv BIT-activemq-2026-34197
https://github.com/apache/activemq affected < 2c1b9eefa68c684083478bfa4a9bcf42892f33ec vendor fix → 2c1b9eefa68c684083478bfa4a9bcf42892f33ec osv
https://github.com/apache/activemq affected >= 14bac13f40958c1a1d3d198051eed32facc4abd1, < d8ce71364638fe4a18ae7531bd1f69f7543e2f16 vendor fix → d8ce71364638fe4a18ae7531bd1f69f7543e2f16 osv
org.apache.activemq:activemq-all affected < 5.19.5 vendor fix → 5.19.5 osv GHSA-rxpj-7qvf-xv32
org.apache.activemq:activemq-all affected >= 6.0.0, < 6.2.3 vendor fix → 6.2.3 osv GHSA-rxpj-7qvf-xv32
org.apache.activemq:activemq-broker affected < 5.19.5 vendor fix → 5.19.5 osv GHSA-rxpj-7qvf-xv32
org.apache.activemq:activemq-broker affected >= 6.0.0, < 6.2.3 vendor fix → 6.2.3 osv GHSA-rxpj-7qvf-xv32
activemq fixed 5.19.4 vendor fix → 5.19.4 osv BIT-activemq-2026-34197
activemq fixed 6.2.3 vendor fix → 6.2.3 osv BIT-activemq-2026-34197
https://github.com/apache/activemq fixed 2c1b9eefa68c684083478bfa4a9bcf42892f33ec vendor fix → 2c1b9eefa68c684083478bfa4a9bcf42892f33ec osv
https://github.com/apache/activemq fixed d8ce71364638fe4a18ae7531bd1f69f7543e2f16 vendor fix → d8ce71364638fe4a18ae7531bd1f69f7543e2f16 osv
org.apache.activemq:activemq-all fixed 5.19.5 vendor fix → 5.19.5 osv GHSA-rxpj-7qvf-xv32
org.apache.activemq:activemq-all fixed 6.2.3 vendor fix → 6.2.3 osv GHSA-rxpj-7qvf-xv32
org.apache.activemq:activemq-broker fixed 5.19.5 vendor fix → 5.19.5 osv GHSA-rxpj-7qvf-xv32
org.apache.activemq:activemq-broker fixed 6.2.3 vendor fix → 6.2.3 osv GHSA-rxpj-7qvf-xv32
Apache Software Foundation/Apache ActiveMQ/org.apache.activemq:apache-activemq Apache Software Foundation · Apache ActiveMQ affected < 5.19.4 none available cve_cna
Apache Software Foundation/Apache ActiveMQ/org.apache.activemq:apache-activemq Apache Software Foundation · Apache ActiveMQ affected >= 6.0.0, < 6.2.3 none available cve_cna
Apache Software Foundation/Apache ActiveMQ All/org.apache.activemq:activemq-all Apache Software Foundation · Apache ActiveMQ All affected < 5.19.4 none available cve_cna
Apache Software Foundation/Apache ActiveMQ All/org.apache.activemq:activemq-all Apache Software Foundation · Apache ActiveMQ All affected >= 6.0.0, < 6.2.3 none available cve_cna
Apache Software Foundation/Apache ActiveMQ Broker/org.apache.activemq:activemq-broker Apache Software Foundation · Apache ActiveMQ Broker affected < 5.19.4 none available cve_cna
Apache Software Foundation/Apache ActiveMQ Broker/org.apache.activemq:activemq-broker Apache Software Foundation · Apache ActiveMQ Broker affected >= 6.0.0, < 6.2.3 none available cve_cna
Red Hat/Red Hat JBoss Enterprise Application Platform Expansion Pack/activemq-broker Red Hat · Red Hat JBoss Enterprise Application Platform Expansion Pack affected no version stated vendor label: all versions none available cve_adp
Red Hat/Red Hat AMQ Broker 7/activemq-broker Red Hat · Red Hat AMQ Broker 7 not affected no version stated vendor label: all versions not applicable cve_adp
Red Hat/Red Hat Data Grid 8/activemq-broker Red Hat · Red Hat Data Grid 8 not affected no version stated vendor label: all versions not applicable cve_adp
Red Hat/Red Hat Enterprise Linux 8/log4j:2/log4j Red Hat · Red Hat Enterprise Linux 8 not affected no version stated vendor label: all versions not applicable cve_adp
Red Hat/Red Hat Enterprise Linux 9/log4j Red Hat · Red Hat Enterprise Linux 9 not affected no version stated vendor label: all versions not applicable cve_adp
Red Hat/Red Hat Fuse 7/activemq-all Red Hat · Red Hat Fuse 7 not affected no version stated vendor label: all versions not applicable cve_adp
Red Hat/Red Hat Fuse 7/activemq-broker Red Hat · Red Hat Fuse 7 not affected no version stated vendor label: all versions not applicable cve_adp
Red Hat/Red Hat JBoss Enterprise Application Platform 7/activemq-broker Red Hat · Red Hat JBoss Enterprise Application Platform 7 not affected no version stated vendor label: all versions not applicable cve_adp
Red Hat/Red Hat JBoss Enterprise Application Platform 8/activemq-broker Red Hat · Red Hat JBoss Enterprise Application Platform 8 not affected no version stated vendor label: all versions not applicable cve_adp

A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.