logo

Apache ActiveMQ Allow Attackers to Trigger DoS Attacks With Malformed Packets

ID: affcc4a2-028f-5905-8799-eaa412032e98

STIX ID: report--affcc4a2-028f-5905-8799-eaa412032e98

Feed Name: cybersecurityNews.com

Threat Score
50/100

Date Published: 2026-03-06

Date Updated: 2026-04-21

Author: Abinaya

...
...

A medium-severity vulnerability (CVE-2025-66168, CVSS 5.4) in Apache ActiveMQ's MQTT module can allow authenticated attackers to trigger a denial-of-service by sending malformed MQTT packets that exploit an integer overflow in the remaining-length decoding; affected versions include all releases before 5.19.2, 6.0.0–6.1.8, and 6.2.0 — administrators should upgrade to 5.19.2, 6.1.9, or 6.2.1 or temporarily disable the MQTT transport connector as a mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.