Root has patched CVE-2026-42588 in the io.root.org.apache.activemq:activemq-broker package for Root:Maven. Multiple fixed versions available.
{ "distro": "maven", "distro_version": "", "severity": "HIGH", "source": "Root" }
"root.io.12"
[ "5.18.3-root.io.11", "6.1.3-root.io.7", "5.18.3-root.io.12" ]
3.0
"5.18.3"
true
"https://api.root.io/external/osv/ROOT-APP-MAVEN-CVE-2026-42588.json"
[ "5.18.3-aikido.11", "6.1.3-aikido.7", "5.18.3-aikido.12" ]
"5.18.3-aikido.12"
""
"root.io.7"
[ "6.1.3-root.io.7" ]
1.0
"6.1.3"
[ "6.1.3-aikido.7" ]
"6.1.3-aikido.7"