PT-2026-22886 · Apache · Apache Activemq

Published

2026-03-04

·

Updated

2026-04-13

·

CVE-2025-66168

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache ActiveMQ versions prior to 5.19.2 Apache ActiveMQ versions 6.0.0 through 6.1.8 Apache ActiveMQ version 6.2.0
Description Apache ActiveMQ does not properly validate the remaining length field, potentially leading to an integer overflow during the decoding of malformed packets. This overflow can cause ActiveMQ to miscalculate the total Remaining Length and incorrectly interpret the payload as multiple MQTT control packets, resulting in unexpected behavior when interacting with non-compliant clients. This violates the MQTT v3.1.1 specification, which limits Remaining Length to a maximum of 4 bytes. The issue occurs on established connections after authentication. Brokers not using mqtt transport connectors are not impacted.
Recommendations Upgrade to Apache ActiveMQ version 5.19.2. Upgrade to Apache ActiveMQ version 6.1.9. Upgrade to Apache ActiveMQ version 6.2.1.

Fix

Integer Overflow

Weakness Enumeration

Related Identifiers

BIT-ACTIVEMQ-2025-66168
BIT-ACTIVEMQ-2026-40046
CVE-2025-66168
GHSA-C825-6PH3-4H84
GHSA-XVQC-PP94-FMPX
OESA-2026-1607
OESA-2026-1608
OESA-2026-1679
OESA-2026-1680
OESA-2026-1681

Affected Products

Apache Activemq