Integer overflow in ActiveMQ - CVE-2025-66168
Published: March 4, 2026 / Updated: April 10, 2026
Vulnerability details
The vulnerability allows a remote user to perform a denial of service attack.
The vulnerability exists due to integer overflow within the MQTT module when decoding malformed packets. A remote user can send specially crafted packets to the application, trigger an integer overflow and perform a denial of service attack. Note, the vulnerability does not affect brokers with not enabled MQTT transport connectors.
Affected software
IBM Sterling Control Center
IBM Qradar SIEM
openEuler
activemq-javadoc
activemq
How to mitigate CVE-2025-66168
IBM Sterling Control Center - addressed in versions 6.3.1.0.8, 6.4.1.0.2, 6.4.2.0.3
IBM Qradar SIEM - update to 7.5.0 Update Pack 15 IF05
activemq-javadoc - addressed in versions 5.19.2-1, 5.19.6-1
activemq - addressed in versions 5.19.2-1, 5.19.6-1
External References
Related Security Bulletins
- Denial of service in Apache ActiveMQ
- openEuler 24.03 LTS SP2 update for activemq
- openEuler 24.03 LTS SP1 update for activemq
- openEuler 22.03 LTS SP4 update for activemq
- openEuler 24.03 LTS SP3 update for activemq
- openEuler 24.03 LTS update for activemq
- openEuler 24.03 LTS SP3 update for activemq
- openEuler 24.03 LTS SP1 update for activemq
- openEuler 24.03 LTS update for activemq
- openEuler 22.03 LTS SP4 update for activemq
- Multiple vulnerabilities in IBM Sterling Control Center
- Multiple vulnerabilities in IBM QRadar SIEM