AMQ Broker 7.13.6 backports the Artemis security fixes to the 7.13 stream
The Important-rated update gives 7.13 operators fixes for unauthenticated queue actions, session hijacking and cluster credential exposure without moving to 7.14.
Red Hat has released AMQ Broker 7.13.6 as an Important-rated security and maintenance update, giving operators on the 7.13 stream a supported route to the broker-level fixes that also appeared in 7.14.1. The 7.13.6 advisory includes security fixes, bug fixes and enhancements; it does not require a move to the newer 7.14 stream.
What the backport changes
The most consequential fixes are in Apache ActiveMQ Artemis itself. Red Hat lists:
- CVE-2026-49362, unauthenticated queue creation through the Artemis core protocol;
- CVE-2026-57967, session hijacking caused by missing authentication;
- CVE-2026-67593, pre-authentication deletion of arbitrary durable queues through OpenWire;
- CVE-2026-49364, disclosure of the broker cluster password through JGroups spoofing;
- CVE-2026-49363, pre-authentication topology disclosure; and
- CVE-2026-57822, unsafe deserialization on the Artemis management address.
The update also carries fixes across the surrounding broker stack, including a Jolokia JMX-HTTP bridge code-execution flaw, Jackson Databind code-execution paths, Jetty digest-authentication bypass, Netty request smuggling and several denial-of-service conditions in STOMP, MQTT, HTTP, WebSocket and Qpid Proton-J processing.
The 7.13.6 and 7.14.1 advisories substantially overlap, but they are not identical component manifests. The decision is therefore stream-based: install the update built for the AMQ Broker line already in production rather than treating 7.14.1 as a prerequisite.
Who should prioritize it
Teams exposing the core protocol or OpenWire have direct unauthenticated broker-state risks in the fixed set. Clustered brokers should also account for the JGroups credential-disclosure issue, while deployments exposing management, STOMP or MQTT endpoints inherit additional relevant fixes.
Red Hat rates the update Important, not Critical, and the advisory does not claim exploitation in the wild. Even so, unauthenticated queue creation, durable-queue deletion and session hijacking can affect broker integrity and availability, so this is more than routine dependency churn.
Upgrade and verify
Red Hat instructs operators to back up the existing installation, including applications, configuration files, databases and database settings, before applying 7.13.6. The update download requires Customer Portal access.
After upgrading through the supported 7.13 channel, verify the broker version on every node, then retest authentication and authorization for each enabled protocol. Clustered deployments should confirm topology formation and message replication after rolling nodes. Finally, exercise queue creation and deletion with both authorized and unauthenticated clients, and check that existing durable subscriptions and store-and-forward queues remain intact.
The release also fixes reported 7.13 defects involving message loss after a graceful clustered-node restart under high load, an unresponsive Prometheus metrics endpoint, MQTT address deletion, and HTTP-tunneling reply starvation. Those fixes make post-upgrade checks of clustering, metrics and protocol-specific traffic part of the same maintenance window.
sources
- RHSA-2026:66545 — Red Hat AMQ Broker 7.13.6 release and security updateaccess.redhat.com
- RHSA-2026:66488 — Red Hat AMQ Broker 7.14.1 release and security updateaccess.redhat.com
- Release Notes for Red Hat AMQ Broker 7.13docs.redhat.com
comments · 0