Apache Software Foundation Apache Activemq Mqtt vulnerabilities
2 known vulnerabilities affecting apache_software_foundation/apache_activemq_mqtt.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2026-40046MEDIUMCVSS 5.4≥ 6.0.0, < 6.2.42026-04-09
CVE-2026-40046 [MEDIUM] CWE-190 Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT: Missing fix for CVE-2025-66168: MQTT control packet remaining length field is not properly validated
Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT: Missing fix for CVE-2025-66168: MQTT control packet remaining length field is not properly validated
Integer Overflow or Wraparound vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT.
The fix for "CVE-2025-66168: MQTT co
cvelistv5
CVE-2025-66168HIGHCVSS 8.8≥ 6.0.0, < 6.2.42026-03-04
CVE-2025-66168 [MEDIUM] CWE-190 CVE-2025-66168: Apache ActiveMQ does not properly validate the remaining length field which may lead to an overflow
Apache ActiveMQ does not properly validate the remaining length field which may lead to an overflow during the decoding of malformed packets. When this integer overflow occurs, ActiveMQ may incorrectly compute the total Remaining Length and subsequently misinterpret the payload as multiple MQTT control packets which makes the broker susceptible to un
nvd