<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 13:47:34 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-11946</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-11946</link>
      <description>bdu:2026-11946</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-11946</guid>
    </item>
    <item>
      <title>BIT-activemq-2025-66168 — Apache ActiveMQ, Apache ActiveMQ All Module, Apache ActiveMQ MQTT Module: MQTT control packet remaining length field is…</title>
      <link>https://cve.radiocsirt.org/vuln/bit-activemq-2025-66168</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: activemq&lt;/p&gt;
&lt;p&gt;WARNING:&lt;/p&gt;
&lt;p&gt;Users of 6.x should upgrade to 6.2.4 or later as the fix was missed in previous 6.x releases.&lt;/p&gt;
&lt;p&gt;See the  following for more details:
 https://activemq.apache.org/security-advisories.data/CVE-2026-40046-announcement.txt 
 https://www.cve.org/CVERecord?id=CVE-2026-40046&lt;/p&gt;
&lt;p&gt;Original Report:&lt;/p&gt;
&lt;p&gt;Apache ActiveMQ does not properly validate the remaining length field which may lead to an overflow during the decoding of malformed packets. When this integer overflow occurs, ActiveMQ may incorrectly compute the total Remaining Length and subsequently misinterpret the payload as multiple MQTT control packets which makes the broker susceptible to unexpected behavior when interacting with non-compliant clients. This behavior violates the MQTT v3.1.1 specification, which restricts Remaining Length to a maximum of 4 bytes. The scenario occurs on established connections after the authentication process. Brokers that are not enabling mqtt transport connectors are not impacted.&lt;/p&gt;
&lt;p&gt;This issue affects Apache ActiveMQ: before 5.19.2, 6.0.0 to 6.1.8, and 6.2.0&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 5.19.2, 6.1.9, or 6.2.1, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: activemq&lt;/p&gt;
&lt;p&gt;WARNING:&lt;/p&gt;
&lt;p&gt;Users of 6.x should upgrade to 6.2.4 or later as the fix was missed in previous 6.x releases.&lt;/p&gt;
&lt;p&gt;See the  following for more details:
 https://activemq.apache.org/security-advisories.data/CVE-2026-40046-announcement.txt 
 https://www.cve.org/CVERecord?id=CVE-2026-40046&lt;/p&gt;
&lt;p&gt;Original Report:&lt;/p&gt;
&lt;p&gt;Apache ActiveMQ does not properly validate the remaining length field which may lead to an overflow during the decoding of malformed packets. When this integer overflow occurs, ActiveMQ may incorrectly compute the total Remaining Length and subsequently misinterpret the payload as multiple MQTT control packets which makes the broker susceptible to unexpected behavior when interacting with non-compliant clients. This behavior violates the MQTT v3.1.1 specification, which restricts Remaining Length to a maximum of 4 bytes. The scenario occurs on established connections after the authentication process. Brokers that are not enabling mqtt transport connectors are not impacted.&lt;/p&gt;
&lt;p&gt;This issue affects Apache ActiveMQ: before 5.19.2, 6.0.0 to 6.1.8, and 6.2.0&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 5.19.2, 6.1.9, or 6.2.1, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-activemq-2025-66168</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0933 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0933</link>
      <description>certfr-2026-avi-0933</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0933</guid>
    </item>
    <item>
      <title>EUVD-2026-290340</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-290340</link>
      <description>EUVD-2026-290340</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-290340</guid>
    </item>
    <item>
      <title>fkie_cve-2025-66168</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-66168</link>
      <description>&lt;p&gt;WARNING:&lt;/p&gt;
&lt;p&gt;Users of 6.x should upgrade to 6.2.4 or later as the fix was missed in previous 6.x releases.&lt;/p&gt;
&lt;p&gt;See the  following for more details:
 https://activemq.apache.org/security-advisories.data/CVE-2026-40046-announcement.txt 
 https://www.cve.org/CVERecord?id=CVE-2026-40046&lt;/p&gt;
&lt;p&gt;Original Report:&lt;/p&gt;
&lt;p&gt;Apache ActiveMQ does not properly validate the remaining length field which may lead to an overflow during the decoding of malformed packets. When this integer overflow occurs, ActiveMQ may incorrectly compute the total Remaining Length and subsequently misinterpret the payload as multiple MQTT control packets which makes the broker susceptible to unexpected behavior when interacting with non-compliant clients. This behavior violates the MQTT v3.1.1 specification, which restricts Remaining Length to a maximum of 4 bytes. The scenario occurs on established connections after the authentication process. Brokers that are not enabling mqtt transport connectors are not impacted.&lt;/p&gt;
&lt;p&gt;This issue affects Apache ActiveMQ: before 5.19.2, 6.0.0 to 6.1.8, and 6.2.0&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 5.19.2, 6.1.9, or 6.2.1, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;WARNING:&lt;/p&gt;
&lt;p&gt;Users of 6.x should upgrade to 6.2.4 or later as the fix was missed in previous 6.x releases.&lt;/p&gt;
&lt;p&gt;See the  following for more details:
 https://activemq.apache.org/security-advisories.data/CVE-2026-40046-announcement.txt 
 https://www.cve.org/CVERecord?id=CVE-2026-40046&lt;/p&gt;
&lt;p&gt;Original Report:&lt;/p&gt;
&lt;p&gt;Apache ActiveMQ does not properly validate the remaining length field which may lead to an overflow during the decoding of malformed packets. When this integer overflow occurs, ActiveMQ may incorrectly compute the total Remaining Length and subsequently misinterpret the payload as multiple MQTT control packets which makes the broker susceptible to unexpected behavior when interacting with non-compliant clients. This behavior violates the MQTT v3.1.1 specification, which restricts Remaining Length to a maximum of 4 bytes. The scenario occurs on established connections after the authentication process. Brokers that are not enabling mqtt transport connectors are not impacted.&lt;/p&gt;
&lt;p&gt;This issue affects Apache ActiveMQ: before 5.19.2, 6.0.0 to 6.1.8, and 6.2.0&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 5.19.2, 6.1.9, or 6.2.1, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-66168</guid>
    </item>
    <item>
      <title>GHSA-c825-6ph3-4h84 — Apache ActiveMQ is Vulnerable to Integer Overflow or Wraparound</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c825-6ph3-4h84</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.activemq:apache-activemq, Maven: org.apache.activemq:activemq-all, Maven: org.apache.activemq:activemq-mqtt&lt;/p&gt;
&lt;p&gt;Apache ActiveMQ does not properly validate the remaining length field which may lead to an overflow during the decoding of malformed packets. When this integer overflow occurs, ActiveMQ may incorrectly compute the total Remaining Length and subsequently misinterpret the payload as multiple MQTT control packets which makes the broker susceptible to unexpected behavior when interacting with non-compliant clients. This behavior violates the MQTT v3.1.1 specification, which restricts Remaining Length to a maximum of 4 bytes. The scenario occurs on established connections after the authentication process. Brokers that are not enabling mqtt transport connectors are not impacted.&lt;/p&gt;
&lt;p&gt;This issue affects Apache ActiveMQ: before 5.19.2, 6.0.0 to 6.1.8, and 6.2.0&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 5.19.2, 6.1.9, or 6.2.1, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.activemq:apache-activemq, Maven: org.apache.activemq:activemq-all, Maven: org.apache.activemq:activemq-mqtt&lt;/p&gt;
&lt;p&gt;Apache ActiveMQ does not properly validate the remaining length field which may lead to an overflow during the decoding of malformed packets. When this integer overflow occurs, ActiveMQ may incorrectly compute the total Remaining Length and subsequently misinterpret the payload as multiple MQTT control packets which makes the broker susceptible to unexpected behavior when interacting with non-compliant clients. This behavior violates the MQTT v3.1.1 specification, which restricts Remaining Length to a maximum of 4 bytes. The scenario occurs on established connections after the authentication process. Brokers that are not enabling mqtt transport connectors are not impacted.&lt;/p&gt;
&lt;p&gt;This issue affects Apache ActiveMQ: before 5.19.2, 6.0.0 to 6.1.8, and 6.2.0&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 5.19.2, 6.1.9, or 6.2.1, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c825-6ph3-4h84</guid>
    </item>
    <item>
      <title>jvndb-2026-006408</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2026-006408</link>
      <description>&lt;p&gt;Apache ActiveMQ series provided by The Apache Software Foundation does not properly validate the remaining length field of MQTT packets, which may lead to integer overflow and misinterpretation of MQTT packets.&amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/190.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Integer overflow or wraparound (CWE-190) - CVE-2025-66168, CVE-2026-40046&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;Gai Tanaka of Mitsui Bussan Secure Directions, Inc. reported this vulnerability in version 6.2.0 to the developer and IPA under Information Security Early Warning Partnership.&#13;
JPCERT/CC coordinated with the developer to publish the advisory.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache ActiveMQ series provided by The Apache Software Foundation does not properly validate the remaining length field of MQTT packets, which may lead to integer overflow and misinterpretation of MQTT packets.&amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/190.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Integer overflow or wraparound (CWE-190) - CVE-2025-66168, CVE-2026-40046&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;Gai Tanaka of Mitsui Bussan Secure Directions, Inc. reported this vulnerability in version 6.2.0 to the developer and IPA under Information Security Early Warning Partnership.&#13;
JPCERT/CC coordinated with the developer to publish the advisory.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2026-006408</guid>
    </item>
    <item>
      <title>OESA-2026-1607 — activemq security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-1607</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: activemq&lt;/p&gt;
&lt;p&gt;The most popular and powerful open source messaging and Integration Patterns server.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability classified as problematic has been found in Apache ActiveMQ (Application Server Software).CWE is classifying the issue as CWE-190. The product performs a calculation that can produce an integer overflow or wraparound, when the logic assumes that the resulting value will always be larger than the original value. This can introduce other weaknesses when the calculation is used for resource management or execution control.This is going to have an impact on integrity, and availability.Upgrading to version 5.19.2, 6.1.9 or 6.2.1 eliminates this vulnerability.(CVE-2025-66168)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: activemq&lt;/p&gt;
&lt;p&gt;The most popular and powerful open source messaging and Integration Patterns server.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability classified as problematic has been found in Apache ActiveMQ (Application Server Software).CWE is classifying the issue as CWE-190. The product performs a calculation that can produce an integer overflow or wraparound, when the logic assumes that the resulting value will always be larger than the original value. This can introduce other weaknesses when the calculation is used for resource management or execution control.This is going to have an impact on integrity, and availability.Upgrading to version 5.19.2, 6.1.9 or 6.2.1 eliminates this vulnerability.(CVE-2025-66168)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-1607</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-66168</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-66168</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: activemq, Ubuntu:Pro:18.04:LTS: activemq, Ubuntu:Pro:20.04:LTS: activemq, Ubuntu:Pro:22.04:LTS: activemq, Ubuntu:24.04:LTS: activemq, Ubuntu:25.10: activemq, Ubuntu:26.04:LTS: activemq&lt;/p&gt;
&lt;p&gt;WARNING: Users of 6.x should upgrade to 6.2.4 or later as the fix was missed in previous 6.x releases. See the  following for more details: https://activemq.apache.org/security-advisories.data/CVE-2026-40046-announcement.txt  https://www.cve.org/CVERecord?id=CVE-2026-40046 Original Report: Apache ActiveMQ does not properly validate the remaining length field which may lead to an overflow during the decoding of malformed packets. When this integer overflow occurs, ActiveMQ may incorrectly compute the total Remaining Length and subsequently misinterpret the payload as multiple MQTT control packets which makes the broker susceptible to unexpected behavior when interacting with non-compliant clients. This behavior violates the MQTT v3.1.1 specification, which restricts Remaining Length to a maximum of 4 bytes. The scenario occurs on established connections after the authentication process. Brokers that are not enabling mqtt transport connectors are not impacted. This issue affects Apache ActiveMQ: before 5.19.2, 6.0.0 to 6.1.8, and 6.2.0 Users are recommended to upgrade to version 5.19.2, 6.1.9, or 6.2.1, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: activemq, Ubuntu:Pro:18.04:LTS: activemq, Ubuntu:Pro:20.04:LTS: activemq, Ubuntu:Pro:22.04:LTS: activemq, Ubuntu:24.04:LTS: activemq, Ubuntu:25.10: activemq, Ubuntu:26.04:LTS: activemq&lt;/p&gt;
&lt;p&gt;WARNING: Users of 6.x should upgrade to 6.2.4 or later as the fix was missed in previous 6.x releases. See the  following for more details: https://activemq.apache.org/security-advisories.data/CVE-2026-40046-announcement.txt  https://www.cve.org/CVERecord?id=CVE-2026-40046 Original Report: Apache ActiveMQ does not properly validate the remaining length field which may lead to an overflow during the decoding of malformed packets. When this integer overflow occurs, ActiveMQ may incorrectly compute the total Remaining Length and subsequently misinterpret the payload as multiple MQTT control packets which makes the broker susceptible to unexpected behavior when interacting with non-compliant clients. This behavior violates the MQTT v3.1.1 specification, which restricts Remaining Length to a maximum of 4 bytes. The scenario occurs on established connections after the authentication process. Brokers that are not enabling mqtt transport connectors are not impacted. This issue affects Apache ActiveMQ: before 5.19.2, 6.0.0 to 6.1.8, and 6.2.0 Users are recommended to upgrade to version 5.19.2, 6.1.9, or 6.2.1, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-66168</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0591 — Apache ActiveMQ/Artemis: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0591</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Apache ActiveMQ/Artemis ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Apache ActiveMQ/Artemis ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0591</guid>
    </item>
  </channel>
</rss>
