{"id":"CVE-2022-23913","aliases":["GHSA-pr38-qpxm-g88x"],"url":"https://o3.security/vulnerability/CVE-2022-23913","summary":"Apache ActiveMQ Artemis DoS","details":"In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an attacker could partially disrupt availability (DoS) through uncontrolled resource consumption of memory.","published":"2022-02-04T22:33:01Z","modified":"2026-08-12T03:51:26.080443816Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.activemq:artemis-core-client","fixedVersion":"2.19.1"}],"fix":{"url":"https://github.com/apache/activemq-artemis/pull/3862","label":"apache/activemq-artemis#3862"},"references":[{"type":"WEB","url":"https://lists.apache.org/thread/fjynj57rd99s814rdn5hzvmx8lz403q2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23913.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23913"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20220303-0003/"},{"type":"WEB","url":"https://github.com/github/codeql-java-CVE-coverage/issues/1061"},{"type":"WEB","url":"https://github.com/apache/activemq-artemis/pull/3862"},{"type":"WEB","url":"https://github.com/apache/activemq-artemis/pull/3862/commits/1f92368240229b8f5db92a92a72c703faf83e9b7"},{"type":"WEB","url":"https://github.com/apache/activemq-artemis/pull/3871"},{"type":"WEB","url":"https://github.com/apache/activemq-artemis/pull/3871/commits/153d2e9a979aead8dff95fbc91d659ecc7d0fb82"},{"type":"PACKAGE","url":"https://github.com/apache/activemq-artemis"},{"type":"WEB","url":"https://issues.apache.org/jira/browse/ARTEMIS-3593"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20220303-0003"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:26.080443816Z"}}