Integer Overflow or Wraparound Affecting org.apache.activemq:activemq-mqtt package, versions [,5.19.2)[6.0.0,6.2.4)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.78% (51st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGAPACHEACTIVEMQ-15426349
  • published5 Mar 2026
  • disclosed4 Mar 2026
  • creditGai Tanaka

Introduced: 4 Mar 2026

CVE-2025-66168  (opens in a new tab)
CVE-2026-40046  (opens in a new tab)
CWE-190  (opens in a new tab)

How to fix?

Upgrade org.apache.activemq:activemq-mqtt to version 5.19.2, 6.2.4 or higher.

Overview

Affected versions of this package are vulnerable to Integer Overflow or Wraparound when decoding malformed MQTT packets, due to improper validation of the Remaining Length. An attacker can cause the broker to misinterpret payloads as multiple MQTT control packets by sending malicious packets.

Note:

This is only exploitable if the MQTT transport connector is enabled.

This issue got CVE-2026-40046 assigned specifically to track backports to 6.x.x version line.

CVSS Base Scores

version 4.0
version 3.1