Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <bcbd7140-4104-e130-0c86-ce5df8acb131@apache.org>
Date: Thu, 09 Apr 2026 12:44:03 +0000
From: "Christopher L. Shannon" <cshannon@...che.org>
To: oss-security@...ts.openwall.com
Subject: CVE-2026-40046: Apache ActiveMQ, Apache ActiveMQ All, Apache
 ActiveMQ MQTT: Missing fix for CVE-2025-66168: MQTT control packet
 remaining length field is not properly validated 

Severity: moderate 

Affected versions:

- Apache ActiveMQ (org.apache.activemq:apache-activemq) 6.0.0 before 6.2.4
- Apache ActiveMQ All (org.apache.activemq:activemq-all) 6.0.0 before 6.2.4
- Apache ActiveMQ MQTT (org.apache.activemq:activemq-mqtt) 6.0.0 before 6.2.4

Description:

Integer Overflow or Wraparound vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT.

The fix for "CVE-2025-66168: MQTT control packet remaining length field is not properly validated" was only applied to 5.19.2 (and future 5.19.x) releases but was missed for all 6.0.0+ versions.


This issue affects Apache ActiveMQ: from 6.0.0 before 6.2.4; Apache ActiveMQ All: from 6.0.0 before 6.2.4; Apache ActiveMQ MQTT: from 6.0.0 before 6.2.4.



Users are recommended to upgrade to version 6.2.4 or a 5.19.x version starting with 5.19.2 or later (currently latest is 5.19.5), which fixes the issue.

Credit:

Adrien Bernard (finder)

References:

https://www.cve.org/CVERecord?id=CVE-2025-66168
https://activemq.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-40046

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.