CVE-2025-27533

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
07/05/2025
Last modified:
18/07/2025

Description

Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ.<br /> <br /> During unmarshalling of OpenWire commands the size value of buffers was not properly validated which could lead to excessive memory allocation and be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on the availability of the ActiveMQ broker when not using mutual TLS connections.<br /> This issue affects Apache ActiveMQ: from 6.0.0 before 6.1.6, from 5.18.0 before 5.18.7, from 5.17.0 before 5.17.7, before 5.16.8. ActiveMQ 5.19.0 is not affected.<br /> <br /> Users are recommended to upgrade to version 6.1.6+, 5.19.0+, 5.18.7+, 5.17.7, or 5.16.8 or which fixes the issue.<br /> <br /> Existing users may implement mutual TLS to mitigate the risk on affected brokers.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:* 5.16.0 (including) 5.16.8 (excluding)
cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:* 5.17.0 (including) 5.17.7 (excluding)
cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:* 5.18.0 (including) 5.18.7 (excluding)
cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:* 6.0.0 (including) 6.1.6 (excluding)