Repository navigation
Releases: c0dem4sters/CVE-2026-57967
Releases · c0dem4sters/CVE-2026-57967
Release list
v1.0 — CVE-2026-57967 PoC
CVE-2026-57967 — Apache ActiveMQ Artemis SESSION_REATTACH Session Hijacking
Unauthenticated remote hijacking of authenticated CORE-protocol sessions in Apache ActiveMQ Artemis 2.50.0 – 2.56.0. Fixed in 2.57.0 (ARTEMIS-6245).
What's included
- Python exploit (
exploit.py) — stdlib only, zero dependencies - Go exploit (
go/main.go) — compiles to a single static binary - Nuclei template (
nuclei/) — automated vulnerability detection - Session sniffer (
tools/sniffer.py) — passive CORE session name extraction - Version checker (
tools/check.sh) — quick bash probe, requires only nc - Docker lab (
stand/) — vulnerable 2.56.0 + patched 2.57.0 brokers - Victim client (
victim/) — Java demo client for end-to-end reproduction - README in English, Russian, and Chinese
Quick start
cd stand && docker compose up -d && cd ..
./demo.sh