CVE-2025-27533
Apache ActiveMQ OpenWire unmarshalling allocates memory from an unchecked buffer size
Technology
Apache ActiveMQ
CVSS Score
7.5 / 10.0
Affected Versions
before 5.16.8; 5.17.0 before 5.17.7; 5.18.0 before 5.18.7; 6.0.0 before 6.1.6 (5.19.0 and later are not affected)
Upstream Fix
5.16.8, 5.17.7, 5.18.7, 6.1.6
Published
May 7, 2025
OSSeva Coverage
Fixed upstream
Description
During unmarshalling of OpenWire commands the broker did not validate buffer size values, so a client could make it allocate excessive memory and deny service. Brokers that require mutual TLS are protected. The March 2025 releases that fixed it were the last on 5.16, 5.17 and 5.18.
Is your Apache ActiveMQ deployment affected?
If you're running before 5.16.8; 5.17.0 before 5.17.7; 5.18.0 before 5.18.7; 6.0.0 before 6.1.6 (5.19.0 and later are not affected), you need this patch. Book a discovery call to get covered.