Apache ActiveMQ Flaw Enables DoS Attacks via Malformed Network Packets
ID: 405a84ac-2d1f-5dca-bbdc-eed60676e75c
STIX ID: report--405a84ac-2d1f-5dca-bbdc-eed60676e75c
Feed Name: GBHackers
Security researchers disclosed CVE-2025-66168, a packet-validation vulnerability in Apache ActiveMQ's MQTT module that allows authenticated attackers to send malformed MQTT packets causing an integer overflow in length decoding and potentially trigger a denial-of-service; affected versions include any release older than 5.19.2, the 6.0.0 series through 6.1.8, and 6.2.0, and Apache has released patches (5.19.2, 6.1.9, 6.2.1) and recommends disabling MQTT connectors if immediate patching is not possible.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
