live wire
▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel
upstreambeat.ai
newsDATA

AMQ Broker 7.14.1 turns a cluster of Artemis flaws into an upgrade decision

Red Hat’s first 7.14 maintenance release packages fixes for unauthenticated broker actions, session hijacking and code-execution paths.

Before-and-after AMQ Broker upgrade with security fixes.
AI-generated illustration
By The News Desk· Sep 11, 2026the quick take — two AI hosts go live when you do

Red Hat has released AMQ Broker 7.14.1 as an Important-rated security and maintenance update. The advisory says the release includes security fixes, bug fixes and enhancements, turning a long list of component-level vulnerabilities into one supported broker update.

What changed

The most consequential fixes sit in the broker’s authentication and management paths. Red Hat lists an Apache Artemis session-hijacking flaw caused by missing authentication, unauthenticated queue creation through the core protocol, a cluster-password leak through JGroups spoofing and pre-authentication deletion of durable queues through OpenWire.

The update also addresses an arbitrary-code-execution path in the Jolokia JMX-HTTP bridge, two Jackson Databind code-execution flaws and a Jetty digest-authentication bypass. Additional fixes cover HTTP request smuggling and header injection in Netty, proxy-credential disclosure in Axios, several WebSocket and HTTP/2 denial-of-service conditions, and multiple unsafe parsing or deserialization paths.

Red Hat rates the update Important, not Critical. That aggregate rating should not obscure the operational point: several listed issues cross authentication boundaries or permit unauthenticated changes to broker state.

Who is affected

The advisory applies to Red Hat AMQ Broker 7.14. AMQ Broker is Red Hat’s supported messaging product based on Apache ActiveMQ Artemis, and the 7.14 documentation covers both standalone broker administration and deployment on OpenShift.

Teams exposing OpenWire, STOMP, MQTT, the core protocol or the management console have the broadest set of relevant fixes to evaluate. The exact exposure still depends on which protocols and management surfaces a deployment enables.

What to do

Red Hat directs customers to back up the existing installation — including applications, configuration files, databases and database settings — before applying the update. The 7.14.1 download requires Customer Portal access.

Operators should treat this as a broker upgrade rather than a checklist of individual library patches: inventory protocol listeners and management endpoints, confirm that backups can be restored, apply 7.14.1 through the supported channel, and then retest client connections and broker clustering. For teams that previously triaged the individual Artemis flaws, the important new fact is that a supported AMQ Broker update containing the fixes is now available.

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.