Integer overflow in ActiveMQ - CVE-2025-66168
Published: March 4, 2026 / Updated: April 10, 2026
Vulnerability details
The vulnerability allows a remote user to perform a denial of service attack.
The vulnerability exists due to integer overflow within the MQTT module when decoding malformed packets. A remote user can send specially crafted packets to the application, trigger an integer overflow and perform a denial of service attack. Note, the vulnerability does not affect brokers with not enabled MQTT transport connectors.
Affected software
IBM Sterling Control Center
IBM Qradar SIEM
openEuler
Dell EMC OpenManage Enterprise Modular
activemq-javadoc
activemq
How to mitigate CVE-2025-66168
IBM Sterling Control Center - addressed in versions 6.3.1.0.8, 6.4.1.0.2, 6.4.2.0.3
IBM Qradar SIEM - update to 7.5.0 Update Pack 15 IF05
Dell EMC OpenManage Enterprise Modular - update to 2.20.20
activemq-javadoc - addressed in versions 5.19.2-1, 5.19.6-1
activemq - addressed in versions 5.19.2-1, 5.19.6-1
External References
Related Security Bulletins
- Denial of service in Apache ActiveMQ
- openEuler 24.03 LTS SP2 update for activemq
- openEuler 24.03 LTS SP1 update for activemq
- openEuler 22.03 LTS SP4 update for activemq
- openEuler 24.03 LTS SP3 update for activemq
- openEuler 24.03 LTS update for activemq
- openEuler 24.03 LTS SP3 update for activemq
- openEuler 24.03 LTS SP1 update for activemq
- openEuler 24.03 LTS update for activemq
- openEuler 22.03 LTS SP4 update for activemq
- Multiple vulnerabilities in IBM Sterling Control Center
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Dell OpenManage Enterprise Modular