[Japanese]

JVNDB-2026-006408

Apache ActiveMQ series improper validation of MQTT packets [AMQ-9810]

Overview

Apache ActiveMQ series provided by The Apache Software Foundation does not properly validate the remaining length field of MQTT packets, which may lead to integer overflow and misinterpretation of MQTT packets.
  • Integer overflow or wraparound (CWE-190) - CVE-2025-66168, CVE-2026-40046
Gai Tanaka of Mitsui Bussan Secure Directions, Inc. reported this vulnerability in version 6.2.0 to the developer and IPA under Information Security Early Warning Partnership.
JPCERT/CC coordinated with the developer to publish the advisory.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 5.4 (Medium) [IPA Score]
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact: Low
  • Integrity Impact: Low
  • Availability Impact: None
CVSS v4 Severity
Base Metrics: 5.3 (Medium) [IPA Score]
  • Access Vector (AV): Network
  • Attack Complexity (AC): Low
  • Attack Requirements (AT): None
  • Privileges Required (PR): Low
  • User Interaction (UI): None
  • Vulnerable System Impact
  • Confidentiality Impact (VC): Low
  • Integrity Impact (VI): Low
  • Availability Impact (VA): None
  • Subsequent System Impact
  • Confidentiality Impact (SC): None
  • Integrity Impact (SI): None
  • Availability Impact (SA): None
Affected Products


Apache Software Foundation
  • Apache ActiveMQ 5.x versions prior to 5.19.2
  • Apache ActiveMQ 6.x versions prior to 6.2.4
  • Apache ActiveMQ All module 5.x versions prior to 5.19.2
  • Apache ActiveMQ 6.x versions prior to 6.2.4
  • Apache ActiveMQ MQTT module 5.x versions prior to 5.19.2
  • Apache ActiveMQ MQTT 6.x versions prior to 6.2.4

Impact

Processing a crafted MQTT packet may lead to misinterpretation of the packet and unexpected behavior.
Solution

[Update the Software]
Update the software to the latest version according to the information provided by the developer.
Vendor Information

Apache Software Foundation
CWE (What is CWE?)

  1. No Mapping(CWE-Other) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2025-66168
  2. CVE-2026-40046
References

  1. JVN : JVN#20669184
  2. National Vulnerability Database (NVD) : CVE-2025-66168
Revision History

  • [2026/04/24]
      Web page was published