CVE-2025-27533
published 2025-05-07CVE-2025-27533: Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. During unmarshalling of OpenWire commands the size value of buffers was not…
PriorityP357high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EXPLOIT
EPSS
8.45%
94.4th percentile
Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ.
During unmarshalling of OpenWire commands the size value of buffers was not properly validated which could lead to excessive memory allocation and be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on the availability of the ActiveMQ broker when not using mutual TLS connections.
This issue affects Apache ActiveMQ: from 6.0.0 before 6.1.6, from 5.18.0 before 5.18.7, from 5.17.0 before 5.17.7, before 5.16.8. ActiveMQ 5.19.0 is not affected.
Users are recommended to upgrade to version 6.1.6+, 5.19.0+, 5.18.7+, 5.17.7, or 5.16.8 or which fixes the issue.
Existing users may implement mutual TLS to mitigate the risk on affected brokers.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | activemq | >= 0 < 5.16.1-1+deb11u2 | 5.16.1-1+deb11u2 |
| apache | activemq | >= 0 < 5.17.6+dfsg-2 | 5.17.6+dfsg-2 |
| apache | activemq | >= 5.16.0 < 5.16.8 | 5.16.8 |
| apache | activemq | >= 5.17.0 < 5.17.7 | 5.17.7 |
| apache | activemq | >= 5.18.0 < 5.18.7 | 5.18.7 |
| apache | activemq | >= 6.0.0 < 6.1.6 | 6.1.6 |
| apache_software_foundation | apache_activemq | >= 5.16.0 < 5.16.8 | 5.16.8 |
| apache_software_foundation | apache_activemq | >= 5.17.0 < 5.17.7 | 5.17.7 |
| apache_software_foundation | apache_activemq | >= 5.18.0 < 5.18.7 | 5.18.7 |
| apache_software_foundation | apache_activemq | >= 6.0.0 < 6.1.6 | 6.1.6 |
| debian | activemq | < activemq 5.16.1-1+deb11u2 (bullseye) | activemq 5.16.1-1+deb11u2 (bullseye) |
| msrc | azl3_cmake_3.21.4-10_on_azure_linux_3.0 | — | — |
| msrc | azl3_cmake_3.28.2-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_rust_1.75.0-14_on_azure_linux_3.0 | — | — |
| msrc | azl3_rust_1.86.0-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_tensorflow_2.11.1-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_tensorflow_2.16.1-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_cmake_3.21.4-12_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_curl_8.0.1-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_mysql_8.0.34-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_rust_1.72.0-2_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_tensorflow_2.11.1-2_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:D/RE:M/U:Red
osv6.9MEDIUM
vendor_msrc8.8HIGH
vendor_oracle7.5MEDIUM
vendor_debian6.9MEDIUM
vendor_redhat6.9MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Risk Matrix: Third Party (Apache ActiveMQ) — CVE-2025-27533
vendor_oracle·2026-01-15·CVSS 7.5
CVE-2025-27533 [MEDIUM] Oracle Oracle Communications Risk Matrix: Third Party (Apache ActiveMQ) — CVE-2025-27533
Oracle Oracle Communications Risk Matrix: Third Party (Apache ActiveMQ) vulnerability
CVE: CVE-2025-27533
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2026 (JAN 2026)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (Apache ActiveMQ) — CVE-2025-27533
vendor_oracle·2025-10-15·CVSS 4.9
CVE-2025-27533 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Core (Apache ActiveMQ) — CVE-2025-27533
Oracle Oracle Communications Applications Risk Matrix: Core (Apache ActiveMQ) vulnerability
CVE: CVE-2025-27533
CVSS: 4.9
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuoct2025 (OCT 2025)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Microservices (Apache ActiveMQ) — CVE-2025-27533
vendor_oracle·2025-07-15·CVSS 4.9
CVE-2025-27533 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Microservices (Apache ActiveMQ) — CVE-2025-27533
Oracle Oracle Communications Applications Risk Matrix: Microservices (Apache ActiveMQ) vulnerability
CVE: CVE-2025-27533
CVSS: 4.9
Protocol: HTTPS
Remote exploit: No
Affected versions: Network
Advisory: cpujul2025 (JUL 2025)
Red Hat
ActiveMQ: ActiveMQ: Unvalidated Buffer Size Allocation
vendor_redhat·2025-05-07·CVSS 6.9
CVE-2025-27533 [MEDIUM] CWE-789 ActiveMQ: ActiveMQ: Unvalidated Buffer Size Allocation
ActiveMQ: ActiveMQ: Unvalidated Buffer Size Allocation
Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ.
During unmarshalling of OpenWire commands the size value of buffers was not properly validated which could lead to excessive memory allocation and be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on the availability of the ActiveMQ broker when not using mutual TLS connections.
This issue affects Apache ActiveMQ: from 6.0.0 before 6.1.6, from 5.18.0 before 5.18.7, from 5.17.0 before 5.17.7, before 5.16.8. ActiveMQ 5.19.0 is not affected.
Users are recommended to upgrade to version 6.1.6+, 5.19.0+, 5.18.7+, 5.17.7, or 5.16.8 or which fixes the issue.
Existing users may implement
Debian
CVE-2025-27533: activemq - Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. D...
vendor_debian·2025·CVSS 6.9
CVE-2025-27533 [MEDIUM] CVE-2025-27533: activemq - Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. D...
Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. During unmarshalling of OpenWire commands the size value of buffers was not properly validated which could lead to excessive memory allocation and be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on the availability of the ActiveMQ broker when not using mutual TLS connections. This issue affects Apache ActiveMQ: from 6.0.0 before 6.1.6, from 5.18.0 before 5.18.7, from 5.17.0 before 5.17.7, before 5.16.8. ActiveMQ 5.19.0 is not affected. Users are recommended to upgrade to version 6.1.6+, 5.19.0+, 5.18.7+, 5.17.7, or 5.16.8 or which fixes the issue. Existing users may implement mutual TLS to mitigate the risk on affected brokers.
Sco
Microsoft
A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server
vendor_msrc·2023-03-14·CVSS 8.8
CVE-2023-27533 [HIGH] CWE-74 A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server
A vulnerability in input validation exists in curl Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
hackerone: hackerone
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.mi
OSV
Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation
osv·2025-05-07
CVE-2025-27533 [MEDIUM] Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation
Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation
Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ.
During unmarshalling of OpenWire commands the size value of buffers was not properly validated which could lead to excessive memory allocation and be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on the availability of the ActiveMQ broker when not using mutual TLS connections.
This issue affects Apache ActiveMQ: from 6.0.0 before 6.1.6, from 5.18.0 before 5.18.7, from 5.17.0 before 5.17.7, before 5.16.8. ActiveMQ 5.19.0 is not affected.
Users are recommended to upgrade to version 6.1.6+, 5.19.0+, 5.18.7+, 5.17.7, or 5.16.8 or which fixes the issue.
Ex
GHSA
Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation
ghsa·2025-05-07
CVE-2025-27533 [MEDIUM] CWE-789 Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation
Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation
Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ.
During unmarshalling of OpenWire commands the size value of buffers was not properly validated which could lead to excessive memory allocation and be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on the availability of the ActiveMQ broker when not using mutual TLS connections.
This issue affects Apache ActiveMQ: from 6.0.0 before 6.1.6, from 5.18.0 before 5.18.7, from 5.17.0 before 5.17.7, before 5.16.8. ActiveMQ 5.19.0 is not affected.
Users are recommended to upgrade to version 6.1.6+, 5.19.0+, 5.18.7+, 5.17.7, or 5.16.8 or which fixes the issue.
Ex
OSV
CVE-2025-27533: Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ
osv·2025-05-07·CVSS 6.9
CVE-2025-27533 [MEDIUM] CVE-2025-27533: Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ
Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. During unmarshalling of OpenWire commands the size value of buffers was not properly validated which could lead to excessive memory allocation and be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on the availability of the ActiveMQ broker when not using mutual TLS connections. This issue affects Apache ActiveMQ: from 6.0.0 before 6.1.6, from 5.18.0 before 5.18.7, from 5.17.0 before 5.17.7, before 5.16.8. ActiveMQ 5.19.0 is not affected. Users are recommended to upgrade to version 6.1.6+, 5.19.0+, 5.18.7+, 5.17.7, or 5.16.8 or which fixes the issue. Existing users may implement mutual TLS to mitigate the risk on affected brokers.
No detection rules found.
Wiz
CVE-2026-34197 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-34197 [HIGH] CVE-2026-34197 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-34197 :
Apache ActiveMQ Classic vulnerability analysis and mitigation
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ.
Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including
BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String).
An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport's brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext.
Because Spring's ResourceXmlApplicationContext insta
Bugzilla
CVE-2025-27533 ActiveMQ: ActiveMQ: Unvalidated Buffer Size Allocation
bugzilla·2025-05-07·CVSS 6.9
CVE-2025-27533 [MEDIUM] CVE-2025-27533 ActiveMQ: ActiveMQ: Unvalidated Buffer Size Allocation
CVE-2025-27533 ActiveMQ: ActiveMQ: Unvalidated Buffer Size Allocation
Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ.
During unmarshalling of OpenWire commands the size value of buffers was not properly validated which could lead to excessive memory allocation and be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on the availability of the ActiveMQ broker when not using mutual TLS connections.
This issue affects Apache ActiveMQ: from 6.0.0 before 6.1.6, from 5.18.0 before 5.18.7, from 5.17.0 before 5.17.7, before 5.16.8. ActiveMQ 5.19.0 is not affected.
Users are recommended to upgrade to version 6.1.6+, 5.19.0+, 5.18.7+, 5.17.7, or 5.16.8 or which fixes the issue.
Existing us
2025-05-07
Published