<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T15:33:03.170661+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-11946</id>
    <title>bdu:2026-11946</title>
    <updated>2026-10-03T15:33:03.426652+00:00</updated>
    <content>bdu:2026-11946</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-11946"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-activemq-2025-66168</id>
    <title>BIT-activemq-2025-66168 — Apache ActiveMQ, Apache ActiveMQ All Module, Apache ActiveMQ MQTT Module: MQTT control packet remaining length field is…</title>
    <updated>2026-10-03T15:33:03.426693+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: activemq</p>
<p>WARNING:</p>
<p>Users of 6.x should upgrade to 6.2.4 or later as the fix was missed in previous 6.x releases.</p>
<p>See the  following for more details:
 https://activemq.apache.org/security-advisories.data/CVE-2026-40046-announcement.txt 
 https://www.cve.org/CVERecord?id=CVE-2026-40046</p>
<p>Original Report:</p>
<p>Apache ActiveMQ does not properly validate the remaining length field which may lead to an overflow during the decoding of malformed packets. When this integer overflow occurs, ActiveMQ may incorrectly compute the total Remaining Length and subsequently misinterpret the payload as multiple MQTT control packets which makes the broker susceptible to unexpected behavior when interacting with non-compliant clients. This behavior violates the MQTT v3.1.1 specification, which restricts Remaining Length to a maximum of 4 bytes. The scenario occurs on established connections after the authentication process. Brokers that are not enabling mqtt transport connectors are not impacted.</p>
<p>This issue affects Apache ActiveMQ: before 5.19.2, 6.0.0 to 6.1.8, and 6.2.0</p>
<p>Users are recommended to upgrade to version 5.19.2, 6.1.9, or 6.2.1, which fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-activemq-2025-66168"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0933</id>
    <title>certfr-2026-avi-0933 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T15:33:03.426742+00:00</updated>
    <content>certfr-2026-avi-0933</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0933"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-290340</id>
    <title>EUVD-2026-290340</title>
    <updated>2026-10-03T15:33:03.426759+00:00</updated>
    <content>EUVD-2026-290340</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-290340"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-66168</id>
    <title>fkie_cve-2025-66168</title>
    <updated>2026-10-03T15:33:03.426771+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>WARNING:</p>
<p>Users of 6.x should upgrade to 6.2.4 or later as the fix was missed in previous 6.x releases.</p>
<p>See the  following for more details:
 https://activemq.apache.org/security-advisories.data/CVE-2026-40046-announcement.txt 
 https://www.cve.org/CVERecord?id=CVE-2026-40046</p>
<p>Original Report:</p>
<p>Apache ActiveMQ does not properly validate the remaining length field which may lead to an overflow during the decoding of malformed packets. When this integer overflow occurs, ActiveMQ may incorrectly compute the total Remaining Length and subsequently misinterpret the payload as multiple MQTT control packets which makes the broker susceptible to unexpected behavior when interacting with non-compliant clients. This behavior violates the MQTT v3.1.1 specification, which restricts Remaining Length to a maximum of 4 bytes. The scenario occurs on established connections after the authentication process. Brokers that are not enabling mqtt transport connectors are not impacted.</p>
<p>This issue affects Apache ActiveMQ: before 5.19.2, 6.0.0 to 6.1.8, and 6.2.0</p>
<p>Users are recommended to upgrade to version 5.19.2, 6.1.9, or 6.2.1, which fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-66168"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-c825-6ph3-4h84</id>
    <title>GHSA-c825-6ph3-4h84 — Apache ActiveMQ is Vulnerable to Integer Overflow or Wraparound</title>
    <updated>2026-10-03T15:33:03.426802+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.activemq:apache-activemq, Maven: org.apache.activemq:activemq-all, Maven: org.apache.activemq:activemq-mqtt</p>
<p>Apache ActiveMQ does not properly validate the remaining length field which may lead to an overflow during the decoding of malformed packets. When this integer overflow occurs, ActiveMQ may incorrectly compute the total Remaining Length and subsequently misinterpret the payload as multiple MQTT control packets which makes the broker susceptible to unexpected behavior when interacting with non-compliant clients. This behavior violates the MQTT v3.1.1 specification, which restricts Remaining Length to a maximum of 4 bytes. The scenario occurs on established connections after the authentication process. Brokers that are not enabling mqtt transport connectors are not impacted.</p>
<p>This issue affects Apache ActiveMQ: before 5.19.2, 6.0.0 to 6.1.8, and 6.2.0</p>
<p>Users are recommended to upgrade to version 5.19.2, 6.1.9, or 6.2.1, which fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-c825-6ph3-4h84"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2026-006408</id>
    <title>jvndb-2026-006408</title>
    <updated>2026-10-03T15:33:03.426835+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Apache ActiveMQ series provided by The Apache Software Foundation does not properly validate the remaining length field of MQTT packets, which may lead to integer overflow and misinterpretation of MQTT packets.&lt;a href='https://cwe.mitre.org/data/definitions/190.html' target='_blank'&gt;&lt;/a&gt;&lt;ul&gt;&lt;li&gt;Integer overflow or wraparound (CWE-190) - CVE-2025-66168, CVE-2026-40046&lt;/li&gt;&lt;/ul&gt;Gai Tanaka of Mitsui Bussan Secure Directions, Inc. reported this vulnerability in version 6.2.0 to the developer and IPA under Information Security Early Warning Partnership.
JPCERT/CC coordinated with the developer to publish the advisory.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2026-006408"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-1607</id>
    <title>OESA-2026-1607 — activemq security update</title>
    <updated>2026-10-03T15:33:03.426867+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: activemq</p>
<p>The most popular and powerful open source messaging and Integration Patterns server.

Security Fix(es):</p>
<p>A vulnerability classified as problematic has been found in Apache ActiveMQ (Application Server Software).CWE is classifying the issue as CWE-190. The product performs a calculation that can produce an integer overflow or wraparound, when the logic assumes that the resulting value will always be larger than the original value. This can introduce other weaknesses when the calculation is used for resource management or execution control.This is going to have an impact on integrity, and availability.Upgrading to version 5.19.2, 6.1.9 or 6.2.1 eliminates this vulnerability.(CVE-2025-66168)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-1607"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-66168</id>
    <title>UBUNTU-CVE-2025-66168</title>
    <updated>2026-10-03T15:33:03.426892+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: activemq, Ubuntu:Pro:18.04:LTS: activemq, Ubuntu:Pro:20.04:LTS: activemq, Ubuntu:Pro:22.04:LTS: activemq, Ubuntu:24.04:LTS: activemq, Ubuntu:25.10: activemq, Ubuntu:26.04:LTS: activemq</p>
<p>WARNING: Users of 6.x should upgrade to 6.2.4 or later as the fix was missed in previous 6.x releases. See the  following for more details: https://activemq.apache.org/security-advisories.data/CVE-2026-40046-announcement.txt  https://www.cve.org/CVERecord?id=CVE-2026-40046 Original Report: Apache ActiveMQ does not properly validate the remaining length field which may lead to an overflow during the decoding of malformed packets. When this integer overflow occurs, ActiveMQ may incorrectly compute the total Remaining Length and subsequently misinterpret the payload as multiple MQTT control packets which makes the broker susceptible to unexpected behavior when interacting with non-compliant clients. This behavior violates the MQTT v3.1.1 specification, which restricts Remaining Length to a maximum of 4 bytes. The scenario occurs on established connections after the authentication process. Brokers that are not enabling mqtt transport connectors are not impacted. This issue affects Apache ActiveMQ: before 5.19.2, 6.0.0 to 6.1.8, and 6.2.0 Users are recommended to upgrade to version 5.19.2, 6.1.9, or 6.2.1, which fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-66168"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0591</id>
    <title>WID-SEC-W-2026-0591 — Apache ActiveMQ/Artemis: Mehrere Schwachstellen</title>
    <updated>2026-10-03T15:33:03.426925+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Apache ActiveMQ/Artemis ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0591"/>
  </entry>
</feed>
