logo

Apache ActiveMQ Flaw Enables DoS Attacks via Malformed Network Packets

ID: 405a84ac-2d1f-5dca-bbdc-eed60676e75c

STIX ID: report--405a84ac-2d1f-5dca-bbdc-eed60676e75c

Feed Name: GBHackers

Threat Score
60/100

Date Published: 2026-03-06

Date Updated: 2026-04-22

Author: Divya

...
...

Security researchers disclosed CVE-2025-66168, a packet-validation vulnerability in Apache ActiveMQ's MQTT module that allows authenticated attackers to send malformed MQTT packets causing an integer overflow in length decoding and potentially trigger a denial-of-service; affected versions include any release older than 5.19.2, the 6.0.0 series through 6.1.8, and 6.2.0, and Apache has released patches (5.19.2, 6.1.9, 6.2.1) and recommends disabling MQTT connectors if immediate patching is not possible.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.