Skip to content

Releases: c0dem4sters/CVE-2026-57967

v1.0 — CVE-2026-57967 PoC

Choose a tag to compare

@c0dem4sters c0dem4sters released this 06 Oct 20:21

CVE-2026-57967 — Apache ActiveMQ Artemis SESSION_REATTACH Session Hijacking

Unauthenticated remote hijacking of authenticated CORE-protocol sessions in Apache ActiveMQ Artemis 2.50.0 – 2.56.0. Fixed in 2.57.0 (ARTEMIS-6245).

What's included

  • Python exploit (exploit.py) — stdlib only, zero dependencies
  • Go exploit (go/main.go) — compiles to a single static binary
  • Nuclei template (nuclei/) — automated vulnerability detection
  • Session sniffer (tools/sniffer.py) — passive CORE session name extraction
  • Version checker (tools/check.sh) — quick bash probe, requires only nc
  • Docker lab (stand/) — vulnerable 2.56.0 + patched 2.57.0 brokers
  • Victim client (victim/) — Java demo client for end-to-end reproduction
  • README in English, Russian, and Chinese

Quick start

cd stand && docker compose up -d && cd ..
./demo.sh