AMQ Broker 7.14.1 turns a cluster of Artemis flaws into an upgrade decision
Red Hat’s first 7.14 maintenance release packages fixes for unauthenticated broker actions, session hijacking and code-execution paths.
Red Hat has released AMQ Broker 7.14.1 as an Important-rated security and maintenance update. The advisory says the release includes security fixes, bug fixes and enhancements, turning a long list of component-level vulnerabilities into one supported broker update.
What changed
The most consequential fixes sit in the broker’s authentication and management paths. Red Hat lists an Apache Artemis session-hijacking flaw caused by missing authentication, unauthenticated queue creation through the core protocol, a cluster-password leak through JGroups spoofing and pre-authentication deletion of durable queues through OpenWire.
The update also addresses an arbitrary-code-execution path in the Jolokia JMX-HTTP bridge, two Jackson Databind code-execution flaws and a Jetty digest-authentication bypass. Additional fixes cover HTTP request smuggling and header injection in Netty, proxy-credential disclosure in Axios, several WebSocket and HTTP/2 denial-of-service conditions, and multiple unsafe parsing or deserialization paths.
Red Hat rates the update Important, not Critical. That aggregate rating should not obscure the operational point: several listed issues cross authentication boundaries or permit unauthenticated changes to broker state.
Who is affected
The advisory applies to Red Hat AMQ Broker 7.14. AMQ Broker is Red Hat’s supported messaging product based on Apache ActiveMQ Artemis, and the 7.14 documentation covers both standalone broker administration and deployment on OpenShift.
Teams exposing OpenWire, STOMP, MQTT, the core protocol or the management console have the broadest set of relevant fixes to evaluate. The exact exposure still depends on which protocols and management surfaces a deployment enables.
What to do
Red Hat directs customers to back up the existing installation — including applications, configuration files, databases and database settings — before applying the update. The 7.14.1 download requires Customer Portal access.
Operators should treat this as a broker upgrade rather than a checklist of individual library patches: inventory protocol listeners and management endpoints, confirm that backups can be restored, apply 7.14.1 through the supported channel, and then retest client connections and broker clustering. For teams that previously triaged the individual Artemis flaws, the important new fact is that a supported AMQ Broker update containing the fixes is now available.
sources
- RHSA-2026:66488 — Red Hat AMQ Broker 7.14.1 release and security updateaccess.redhat.com
- Release Notes for Red Hat AMQ Broker 7.14docs.redhat.com
comments · 0