Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xvqc-pp94-fmpx

Опубликовано: 09 апр. 2026
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT vulnerable to Integer Overflow or Wraparound

Integer Overflow or Wraparound vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT.

The fix for "CVE-2025-66168: MQTT control packet remaining length field is not properly validated" was only applied to 5.19.2 (and future 5.19.x) releases but was missed for all 6.0.0+ versions. This issue affects Apache ActiveMQ: from 6.0.0 before 6.2.4; Apache ActiveMQ All: from 6.0.0 before 6.2.4; Apache ActiveMQ MQTT: from 6.0.0 before 6.2.4.

Users are recommended to upgrade to version 6.2.4 or a 5.19.x version starting with 5.19.2 or later (currently latest is 5.19.5), which fixes the issue.

Пакеты

Наименование

org.apache.activemq:apache-activemq

maven
Затронутые версииВерсия исправления

>= 6.0.0, < 6.2.4

6.2.4

Наименование

org.apache.activemq:activemq-all

maven
Затронутые версииВерсия исправления

>= 6.0.0, < 6.2.4

6.2.4

Наименование

org.apache.activemq:activemq-mqtt

maven
Затронутые версииВерсия исправления

>= 6.0.0, < 6.2.4

6.2.4

EPSS

Процентиль: 11%
0.00038
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 дней назад

Integer Overflow or Wraparound vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT. The fix for "CVE-2025-66168: MQTT control packet remaining length field is not properly validated" was only applied to 5.19.2 (and future 5.19.x) releases but was missed for all 6.0.0+ versions. This issue affects Apache ActiveMQ: from 6.0.0 before 6.2.4; Apache ActiveMQ All: from 6.0.0 before 6.2.4; Apache ActiveMQ MQTT: from 6.0.0 before 6.2.4. Users are recommended to upgrade to version 6.2.4 or a 5.19.x version starting with 5.19.2 or later (currently latest is 5.19.5), which fixes the issue.

CVSS3: 5.4
redhat
6 дней назад

Integer Overflow or Wraparound vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT. The fix for "CVE-2025-66168: MQTT control packet remaining length field is not properly validated" was only applied to 5.19.2 (and future 5.19.x) releases but was missed for all 6.0.0+ versions. This issue affects Apache ActiveMQ: from 6.0.0 before 6.2.4; Apache ActiveMQ All: from 6.0.0 before 6.2.4; Apache ActiveMQ MQTT: from 6.0.0 before 6.2.4. Users are recommended to upgrade to version 6.2.4 or a 5.19.x version starting with 5.19.2 or later (currently latest is 5.19.5), which fixes the issue.

CVSS3: 7.5
nvd
6 дней назад

Integer Overflow or Wraparound vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT. The fix for "CVE-2025-66168: MQTT control packet remaining length field is not properly validated" was only applied to 5.19.2 (and future 5.19.x) releases but was missed for all 6.0.0+ versions. This issue affects Apache ActiveMQ: from 6.0.0 before 6.2.4; Apache ActiveMQ All: from 6.0.0 before 6.2.4; Apache ActiveMQ MQTT: from 6.0.0 before 6.2.4. Users are recommended to upgrade to version 6.2.4 or a 5.19.x version starting with 5.19.2 or later (currently latest is 5.19.5), which fixes the issue.

CVSS3: 7.5
debian
6 дней назад

Integer Overflow or Wraparound vulnerability in Apache ActiveMQ, Apach ...

EPSS

Процентиль: 11%
0.00038
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-190