logo

Integer Overflow Flaw in Apache ActiveMQ Exposes MQTT Brokers to DoS

ID: 2a1cc9e4-8943-51f2-ba71-2d5e42c85ed3

STIX ID: report--2a1cc9e4-8943-51f2-ba71-2d5e42c85ed3

Feed Name: securityonline.info

Threat Score
60/100

Date Published: 2026-03-05

Date Updated: 2026-04-23

Author: Ddos

...
...

Apache has released a security update for ActiveMQ addressing CVE-2025-66168, an integer overflow in the MQTT transport connector's Remaining Length decoding that can allow authenticated attackers to cause broker desynchronization or denial-of-service by sending malformed MQTT packets; the flaw (CWE-190) affects brokers with MQTT transport connectors enabled (OpenWire, AMQP, or STOMP-only setups are not impacted) and patches are available across three major release branches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.