{"id":"GHSA-xvqc-pp94-fmpx","summary":"Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT vulnerable to Integer Overflow or Wraparound","details":"Integer Overflow or Wraparound vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT.\n\nThe fix for \"CVE-2025-66168: MQTT control packet remaining length field is not properly validated\" was only applied to 5.19.2 (and future 5.19.x) releases but was missed for all 6.0.0+ versions. This issue affects Apache ActiveMQ: from 6.0.0 before 6.2.4; Apache ActiveMQ All: from 6.0.0 before 6.2.4; Apache ActiveMQ MQTT: from 6.0.0 before 6.2.4.\n\nUsers are recommended to upgrade to version 6.2.4 or a 5.19.x version starting with 5.19.2 or later (currently latest is 5.19.5), which fixes the issue.","aliases":["BIT-activemq-2026-40046","CVE-2026-40046"],"modified":"2026-04-13T08:27:19.495842350Z","published":"2026-04-09T18:31:27Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-04-10T14:11:25Z","nvd_published_at":"2026-04-09T17:16:31Z","cwe_ids":["CWE-190"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40046"},{"type":"WEB","url":"https://activemq.apache.org/security-advisories.data/CVE-2026-40046-announcement.txt"},{"type":"WEB","url":"https://lists.apache.org/thread/zdntj5rcgjjzrpow84o339lzldy68zrg"},{"type":"WEB","url":"https://www.cve.org/CVERecord?id=CVE-2025-66168"}],"affected":[{"package":{"name":"org.apache.activemq:apache-activemq","ecosystem":"Maven","purl":"pkg:maven/org.apache.activemq/apache-activemq"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.0.0"},{"fixed":"6.2.4"}]}],"versions":["6.0.0","6.0.1","6.1.0","6.1.1","6.1.2","6.1.3","6.1.4","6.1.5","6.1.6","6.1.7","6.1.8","6.2.0","6.2.1","6.2.2","6.2.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-xvqc-pp94-fmpx/GHSA-xvqc-pp94-fmpx.json"}},{"package":{"name":"org.apache.activemq:activemq-all","ecosystem":"Maven","purl":"pkg:maven/org.apache.activemq/activemq-all"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.0.0"},{"fixed":"6.2.4"}]}],"versions":["6.0.0","6.0.1","6.1.0","6.1.1","6.1.2","6.1.3","6.1.4","6.1.5","6.1.6","6.1.7","6.1.8","6.2.0","6.2.1","6.2.2","6.2.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-xvqc-pp94-fmpx/GHSA-xvqc-pp94-fmpx.json"}},{"package":{"name":"org.apache.activemq:activemq-mqtt","ecosystem":"Maven","purl":"pkg:maven/org.apache.activemq/activemq-mqtt"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.0.0"},{"fixed":"6.2.4"}]}],"versions":["6.0.0","6.0.1","6.1.0","6.1.1","6.1.2","6.1.3","6.1.4","6.1.5","6.1.6","6.1.7","6.1.8","6.2.0","6.2.1","6.2.2","6.2.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-xvqc-pp94-fmpx/GHSA-xvqc-pp94-fmpx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"}]}