CVE-2025-66168: Apache ActiveMQ, Apache ActiveMQ All Module, Apache ActiveMQ MQTT Module: MQTT control packet remaining length field is not properly validated

Published Mar 3, 2026
·
Updated

Apache ActiveMQ does not properly validate the remaining length field which may lead to an overflow during the decoding of malformed packets. When this integer overflow occurs, ActiveMQ may incorrectly compute the total Remaining Length and subsequently misinterpret the payload as multiple MQTT control packets which makes the broker susceptible to unexpected behavior when interacting with non-compliant clients. This behavior violates the MQTT v3.1.1 specification, which restricts Remaining Length to a maximum of 4 bytes. The scenario occurs on established connections after the authentication process. Brokers that are not enabling mqtt transport connectors are not impacted.

This issue affects Apache ActiveMQ: before 5.19.2, 6.0.0 to 6.1.8, and 6.2.0

Users are recommended to upgrade to version 5.19.2, 6.1.9, or 6.2.1, which fixes the issue.

Affected Software

14 affected componentsFixes available
Apache ActiveMQ<5.19.2, >=6.0.0<6.1.8, <6.2.0
maven/org.apache.activemq:activemq-mqtt=6.2.0
6.2.1
maven/org.apache.activemq:activemq-mqtt>=6.0.0<6.1.9
6.1.9
maven/org.apache.activemq:activemq-mqtt<5.19.2
5.19.2
maven/org.apache.activemq:activemq-all=6.2.0
6.2.1
maven/org.apache.activemq:activemq-all>=6.0.0<6.1.9
6.1.9
maven/org.apache.activemq:activemq-all<5.19.2
5.19.2
maven/org.apache.activemq:apache-activemq=6.2.0
6.2.1
maven/org.apache.activemq:apache-activemq>=6.0.0<6.1.9
6.1.9
maven/org.apache.activemq:apache-activemq<5.19.2
5.19.2
Apache ActiveMQ<5.19.2
Apache ActiveMQ>=6.0.0<6.1.9
Apache ActiveMQ=6.2.0
Apache ActiveMQ>=6.0.0<=6.1.8

Event History

Mar 4, 2026
CVE Published
via MITRE·08:45 AM
Data Sourced
via MITRE·08:45 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·09:31 AM
Data Sourced
via GitHub·09:31 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-66168?

The severity of CVE-2025-66168 is considered to be high due to the potential for an overflow during the decoding of malformed MQTT packets.

2

How do I fix CVE-2025-66168?

To fix CVE-2025-66168, you should update Apache ActiveMQ to versions 5.19.2, 6.1.9, or 6.2.1 depending on your current version.

3

Which versions of Apache ActiveMQ are affected by CVE-2025-66168?

CVE-2025-66168 affects Apache ActiveMQ versions prior to 5.19.2, 6.1.9, and 6.2.1.

4

What implications does CVE-2025-66168 pose for MQTT communication?

CVE-2025-66168 may lead to denial of service or unpredictable behavior during MQTT communication due to the improper validation of the remaining length field.

5

Is there a patch available for CVE-2025-66168?

Yes, patches are available in the form of updated versions for affected Apache ActiveMQ components.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203