CVE-2025-54539
Last modified
CVE-2025-54539 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client. This issue affects all versions of Apache ActiveMQ NMS AMQP up to and including 2.3.0, when establishing connections to untrusted AMQP servers. Malicious servers could exploit unbounded deserialization logic present in the client to craft responses that may lead to arbitrary code execution on the client side. Although version 2.1.0 introduced a mechanism to restrict deserialization via allow/deny lists, the protection was found to be bypassable under certain conditions. In line with Microsoft’s deprecation of binary serialization in .NET 9, the project is evaluating the removal of .NET binary serialization support from the NMS API entirely in future releases. Mitigation and Recommendations: Users are strongly encouraged to upgrade to version 2.4.0 or later, which resolves the issue. EPSS estimates a 2.02% chance of exploitation in the next 30 days.
Description
A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client. This issue affects all versions of Apache ActiveMQ NMS AMQP up to and including 2.3.0, when establishing connections to untrusted AMQP servers. Malicious servers could exploit unbounded deserialization logic present in the client to craft responses that may lead to arbitrary code execution on the client side. Although version 2.1.0 introduced a mechanism to restrict deserialization via allow/deny lists, the protection was found to be bypassable under certain conditions. In line with Microsoft’s deprecation of binary serialization in .NET 9, the project is evaluating the removal of .NET binary serialization support from the NMS API entirely in future releases. Mitigation and Recommendations: Users are strongly encouraged to upgrade to version 2.4.0 or later, which resolves the issue. Additionally, projects depending on NMS-AMQP should migrate away from .NET binary serialization as part of a long-term hardening strategy.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Activemq Nms Amqp | < 2.4.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-54539?
How severe is CVE-2025-54539?
How do I fix CVE-2025-54539?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-54533In JetBrains TeamCity before 2025.07 improper access control…4.3
- CVE-2025-54534In JetBrains TeamCity before 2025.07 reflected XSS was possi…4.8
- CVE-2025-54535In JetBrains TeamCity before 2025.07 password reset and emai…7.5
- CVE-2025-54536In JetBrains TeamCity before 2025.07 a CSRF was possible on …8.8
- CVE-2025-54537In JetBrains TeamCity before 2025.07 user credentials were s…5.5
- CVE-2025-54538In JetBrains TeamCity before 2025.07 password exposure was p…5.5
- CVE-2025-5454An ACAP configuration file lacked sufficient input validatio…6.7
- CVE-2025-54540QuickCMS is vulnerable to Reflected XSS via sSort parameter …6.1
- CVE-2025-54541QuickCMS is vulnerable to Cross-Site Request Forgery in page…4.3
- CVE-2025-54542QuickCMS sends password and login via GET Request. This allo…5.5
- CVE-2025-54543QuickCMS is vulnerable to Stored XSS via sDescriptionMeta pa…4.8
- CVE-2025-54544QuickCMS is vulnerable to Stored XSS via aDirFilesDescriptio…4.8
Are you affected by CVE-2025-54539?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
