PT-2026-22886 · Apache+1 · Apache Activemq+1
CVE-2025-66168
·
Published
2026-03-04
·
Updated
2026-07-27
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apache ActiveMQ versions prior to 5.19.2
Apache ActiveMQ versions 6.0.0 through 6.1.8
Apache ActiveMQ version 6.2.0
Description
Apache ActiveMQ fails to properly validate the remaining length field, which can lead to an integer overflow during the decoding of malformed packets. This overflow may cause the broker to incorrectly compute the total remaining length and misinterpret the payload as multiple MQTT control packets, resulting in unexpected behavior or a system crash when interacting with non-compliant clients. This issue violates the MQTT v3.1.1 specification, which limits the remaining length to a maximum of 4 bytes. The flaw is exploitable on established connections after the authentication process. Brokers that do not have MQTT transport connectors enabled are not affected.
Recommendations
Upgrade versions prior to 5.19.2 to version 5.19.2.
Upgrade versions 6.0.0 through 6.1.8 to version 6.1.9.
Upgrade version 6.2.0 to version 6.2.1.
As a temporary mitigation, disable the MQTT transport connector.
Exploit
Fix
DoS
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Activemq
Red Os