PT-2026-22886 · Apache+1 · Apache Activemq+1

CVE-2025-66168

·

Published

2026-03-04

·

Updated

2026-07-27

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache ActiveMQ versions prior to 5.19.2 Apache ActiveMQ versions 6.0.0 through 6.1.8 Apache ActiveMQ version 6.2.0
Description Apache ActiveMQ fails to properly validate the remaining length field, which can lead to an integer overflow during the decoding of malformed packets. This overflow may cause the broker to incorrectly compute the total remaining length and misinterpret the payload as multiple MQTT control packets, resulting in unexpected behavior or a system crash when interacting with non-compliant clients. This issue violates the MQTT v3.1.1 specification, which limits the remaining length to a maximum of 4 bytes. The flaw is exploitable on established connections after the authentication process. Brokers that do not have MQTT transport connectors enabled are not affected.
Recommendations Upgrade versions prior to 5.19.2 to version 5.19.2. Upgrade versions 6.0.0 through 6.1.8 to version 6.1.9. Upgrade version 6.2.0 to version 6.2.1. As a temporary mitigation, disable the MQTT transport connector.

Exploit

Fix

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11946
BIT-ACTIVEMQ-2025-66168
BIT-ACTIVEMQ-2026-40046
CVE-2025-66168
GHSA-C825-6PH3-4H84
GHSA-XVQC-PP94-FMPX
OESA-2026-1607
OESA-2026-1608
OESA-2026-1609
OESA-2026-1610
OESA-2026-1611
OESA-2026-1679
OESA-2026-1680
OESA-2026-1681

Affected Products

Apache Activemq
Red Os