Back to Vulnerability Directory
HIGHFixed upstream

CVE-2025-27533

Apache ActiveMQ OpenWire unmarshalling allocates memory from an unchecked buffer size

Technology

Apache ActiveMQ

CVSS Score

7.5 / 10.0

Affected Versions

before 5.16.8; 5.17.0 before 5.17.7; 5.18.0 before 5.18.7; 6.0.0 before 6.1.6 (5.19.0 and later are not affected)

Upstream Fix

5.16.8, 5.17.7, 5.18.7, 6.1.6

Published

May 7, 2025

OSSeva Coverage

Fixed upstream

Description

During unmarshalling of OpenWire commands the broker did not validate buffer size values, so a client could make it allocate excessive memory and deny service. Brokers that require mutual TLS are protected. The March 2025 releases that fixed it were the last on 5.16, 5.17 and 5.18.

Upstream record: NVD · CVE.org

Is your Apache ActiveMQ deployment affected?

If you're running before 5.16.8; 5.17.0 before 5.17.7; 5.18.0 before 5.18.7; 6.0.0 before 6.1.6 (5.19.0 and later are not affected), you need this patch. Book a discovery call to get covered.