Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2025-27533

CWE-789CWE-7412 documents9 sources
Severity
6.9MEDIUM
EPSS
2.3%
top 15.40%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMay 7
Latest updateJan 15

Description

Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. During unmarshalling of OpenWire commands the size value of buffers was not properly validated which could lead to excessive memory allocation and be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on the availability of the ActiveMQ broker when not using mutual TLS connections. This issue affects Apache ActiveMQ: from 6.0.0 before 6.1.6,

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H

Affected Packages5 packages

NVDapache/activemq5.16.05.16.8+3
Mavenorg.apache.activemq:activemq-client5.17.05.17.7+3
CVEListV5apache_software_foundation/apache_activemq6.0.06.1.6+3
Debianactivemq< 5.16.1-1+deb11u2+1

🔴Vulnerability Details

4
CVEList
Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation2025-05-07
OSV
Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation2025-05-07
GHSA
Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation2025-05-07
OSV
CVE-2025-27533: Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ2025-05-07

💥Exploits & PoCs

1
Exploit-DB
Apache ActiveMQ 6.1.6 - Denial of Service (DOS)2025-05-09

📋Vendor Advisories

6
Oracle
Oracle Oracle Communications Risk Matrix: Third Party (Apache ActiveMQ) — CVE-2025-275332026-01-15
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (Apache ActiveMQ) — CVE-2025-275332025-10-15
Oracle
Oracle Oracle Communications Applications Risk Matrix: Microservices (Apache ActiveMQ) — CVE-2025-275332025-07-15
Red Hat
ActiveMQ: ActiveMQ: Unvalidated Buffer Size Allocation2025-05-07
Debian
CVE-2025-27533: activemq - Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. D...2025