
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-66168 is an integer overflow vulnerability in Apache ActiveMQ's MQTT packet decoder, titled "MQTT control packet remaining length field is not properly validated." It affects Apache ActiveMQ (including the All Module and MQTT Module) before version 5.19.2, versions 6.0.0 through 6.1.8, and version 6.2.0. The vulnerability was disclosed on March 3–4, 2026, with the initial report credited to researcher Gai Tanaka (oss-security). It carries a CVSS v3.1 base score of 8.8 (High) per NVD (Red Hat Bugzilla, Red Hat CVE). Note: A follow-on CVE, CVE-2026-40046, was later issued because the fix for CVE-2025-66168 was missed in all 6.x releases prior to 6.2.4; users of the 6.x branch should upgrade to 6.2.4 or later (Apache Advisory).
The root cause is an integer overflow (CWE-190) combined with improper handling of a length parameter inconsistency (CWE-130) in the MQTT transport connector's packet decoder. When ActiveMQ processes a malformed MQTT packet, it fails to properly validate the "Remaining Length" field, which the MQTT v3.1.1 specification restricts to a maximum of 4 bytes. The overflow causes ActiveMQ to miscalculate the total Remaining Length, leading it to misinterpret a single packet payload as multiple MQTT control packets — a violation of the protocol specification. Exploitation requires an established, authenticated connection over the MQTT transport connector; brokers that do not enable MQTT transport connectors are not affected (oss-security, Red Hat Bugzilla).
Successful exploitation can cause the ActiveMQ broker to exhibit unexpected behavior, including potential denial-of-service conditions, information disclosure, and data integrity issues resulting from misinterpreted packet payloads. The NVD-assigned CVSS score reflects high confidentiality, integrity, and availability impacts, meaning a successful attack could disrupt broker operations, expose message data, or corrupt message routing on established connections. The attack is limited to authenticated sessions over MQTT transport connectors, reducing the attack surface to clients with valid credentials (Red Hat CVE, oss-security).
Apache has released patched versions: 5.19.2, 6.1.9, and 6.2.1 for CVE-2025-66168. However, because the fix was missed in subsequent 6.x releases, users on the 6.x branch should upgrade to 6.2.4 or later (as addressed by CVE-2026-40046) (Apache Advisory). As an immediate workaround, disable MQTT transport connectors on brokers where the MQTT protocol is not required. Additionally, implement network-level access controls to restrict MQTT port access to trusted clients only, and monitor MQTT connections for anomalous or malformed packet activity (oss-security, Red Hat CVE).
Security news outlets including GBHackers, CyberPress, SecurityOnline, and CyberSecurityNews covered the vulnerability, generally framing it as an MQTT-based DoS risk in Apache ActiveMQ (securityonline). The Apache Software Foundation issued the advisory through the oss-security mailing list and credited researcher Gai Tanaka as the finder (oss-security). Red Hat tracked the issue via Bugzilla and assigned medium severity in their own assessment (Red Hat Bugzilla). Community reaction was moderate, with social media posts on Bluesky and Mastodon noting the patch availability and the follow-on CVE-2026-40046 issued due to the incomplete fix in 6.x releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."