Integer overflow in ActiveMQ - CVE-2025-66168

 

Integer overflow in ActiveMQ - CVE-2025-66168

Published: March 4, 2026 / Updated: April 10, 2026


Vulnerability identifier: #VU123488
CSH Severity: Medium
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-66168
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform a denial of service attack.

The vulnerability exists due to integer overflow within the MQTT module when decoding malformed packets. A remote user can send specially crafted packets to the application, trigger an integer overflow and perform a denial of service attack. Note, the vulnerability does not affect brokers with not enabled MQTT transport connectors.


Affected software

ActiveMQ
IBM Sterling Control Center
IBM Qradar SIEM
openEuler
Dell EMC OpenManage Enterprise Modular
activemq-javadoc
activemq

How to mitigate CVE-2025-66168

Install updates from vendor's website.

ActiveMQ - update to 5.19.2
IBM Sterling Control Center - addressed in versions 6.3.1.0.8, 6.4.1.0.2, 6.4.2.0.3
IBM Qradar SIEM - update to 7.5.0 Update Pack 15 IF05
Dell EMC OpenManage Enterprise Modular - update to 2.20.20
activemq-javadoc - addressed in versions 5.19.2-1, 5.19.6-1
activemq - addressed in versions 5.19.2-1, 5.19.6-1

External References

Related Security Bulletins