PT-2025-19995 · Apache+2 · Apache Activemq+2

Christopher L. Shannon

·

Published

2025-05-06

·

Updated

2026-06-02

·

CVE-2025-27533

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache ActiveMQ versions 6.0.0 through 6.1.6 Apache ActiveMQ versions 5.18.0 through 5.18.7 Apache ActiveMQ versions 5.17.0 through 5.17.7 Apache ActiveMQ versions prior to 5.16.8
Description The issue is related to a Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. During unmarshalling of OpenWire commands, the size value of buffers was not properly validated, which could lead to excessive memory allocation and be exploited to cause a denial of service (DoS) by depleting process memory. This affects applications and services that rely on the availability of the ActiveMQ broker when not using mutual TLS connections. It is estimated that over 41.9 million services may be affected.
Recommendations To resolve the issue, upgrade to version 6.1.6 or later. To resolve the issue, upgrade to version 5.19.0 or later. To resolve the issue, upgrade to version 5.18.7 or later. To resolve the issue, upgrade to version 5.17.7 or later. To resolve the issue, upgrade to version 5.16.8 or later. As a temporary workaround, consider implementing mutual TLS to mitigate the risk on affected brokers.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-06024
BIT-ACTIVEMQ-2025-27533
CVE-2025-27533
DLA-4222-1
GHSA-WHXR-3P84-RF3C
OESA-2025-1507

Affected Products

Apache Activemq
Debian
Red Os