Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-27533

38
FAUCET Score

CVE-2025-27533 is a Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ versions 6.0.0 before 6.1.6, 5.18.0 before 5.18.7, 5.17.0 before 5.17.7, and before 5.16.8, where improper validation of buffer size during OpenWire command unmarshalling can lead to excessive memory allocation. This vulnerability has a CVSS score of 7.5 (HIGH), indicating a network-based attack with low complexity that can result in a denial of service by depleting process memory, affecting services relying on the ActiveMQ broker. While not actively exploited in the wild, an ExploitDB entry (EDB-52288) exists for a Denial of Service, and there is minimal community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.16.0, < 5.16.8CPE matchmatch criteria
cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*
>= 5.17.0, < 5.17.7CPE matchmatch criteria
cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*
>= 5.18.0, < 5.18.7CPE matchmatch criteria
cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*
>= 6.0.0, < 6.1.6CPE matchmatch criteria
cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

6.9MEDIUM

CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:D/RE:M/U:Red

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
HIGH
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
HIGH
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
8.45%
Probability of exploitation in next 30 days
EPSS Percentile
94.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-52288 · May 9, 2025
This CVE's current EPSS score of 0.0845 is in the 91st percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (14)

mavenpatch availablevia ghsa
Product: org.apache.activemq:activemq-openwire-legacyFixed in: 5.16.8
mavenpatch availablevia ghsa
Product: org.apache.activemq:activemq-clientFixed in: 5.16.8
mavenpatch availablevia ghsa
Product: org.apache.activemq:activemq-openwire-legacyFixed in: 5.17.7
mavenpatch availablevia ghsa
Product: org.apache.activemq:activemq-openwire-legacyFixed in: 5.18.7
mavenpatch availablevia ghsa
Product: org.apache.activemq:activemq-openwire-legacyFixed in: 6.1.6
mavenpatch availablevia ghsa
Product: org.apache.activemq:activemq-clientFixed in: 5.17.7
mavenpatch availablevia ghsa
Product: org.apache.activemq:activemq-clientFixed in: 5.18.7
mavenpatch availablevia ghsa
Product: org.apache.activemq:activemq-clientFixed in: 6.1.6
redhatpatch availablevia redhat_api
Product: Red Hat AMQ Broker 7.13.2Fixed in: activemq-openwire-legacy
View patch
redhatvendor investigatingvia redhat_api
Product: A-MQ Clients 2Fixed in: activemq-openwire-legacy
redhatvendor investigatingvia redhat_api
Product: Red Hat Data Grid 8Fixed in: activemq-openwire-legacy
redhatvendor investigatingvia redhat_api
Product: Red Hat Fuse 7Fixed in: activemq-openwire-legacy
redhatvendor investigatingvia redhat_api
Product: Red Hat Integration Camel K 1Fixed in: activemq-openwire-legacy
redhatvendor investigatingvia redhat_api
Product: streams for Apache KafkaFixed in: activemq-openwire-legacy

Vendor Advisories (2)

mavenGHSA-whxr-3p84-rf3cmedium

Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation

May 7, 2025
redhatCVE-2025-27533Moderate

ActiveMQ: ActiveMQ: Unvalidated Buffer Size Allocation

May 7, 2025

References

lists.debian.org / debian-lts-announce/2025/06/msg00020.html
openwall.com / lists/oss-security/2025/05/06/1
Mailing ListThird Party Advisory
lists.apache.org / thread/8hcm25vf7mchg4zbbhnlx2lc5bs705hg
Mailing ListVendor Advisory