The Apache Software Foundation has disclosed a critical vulnerability in the Apache ActiveMQ NMS AMQP client that could allow attackers to execute arbitrary code on vulnerable systems.
See also: Vulnerability fixed in Apache DolphinScheduler

Tracked as CVE-2025-54539, this deserialization flaw poses a serious risk to client-based applications for messaging over AMQP protocols. The issue was publicly detailed in an advisory on October 15, 2025, calling for immediate updates to mitigate potential exploits.
The vulnerability stems from improper handling of untrusted data during connections to AMQP servers. Specifically, in versions up to 2.3.0, the client processes unbounded deserialization logic that can be abused by malicious servers.
By crafting specially crafted responses, attackers could enable remote code execution on the client side, potentially compromising entire networks or applications. This deserialization vulnerability has long been a vector for sophisticated attacks, as it bypasses standard input validation and directly manipulates the states of objects in memory.
Efforts at client security were not foolproof. Starting with version 2.1.0, Apache introduced whitelists and blacklists to restrict deserialization, with the goal of limiting which classes could be created from incoming data.
See also: Warning: Critical vulnerability in Apache Jackrabbit

However, security researchers at Endor Labs discovered that these checks could be bypassed under certain circumstances, such as through cleverly embedded objects or alternative serialization paths.
This bypass effectively nullified the protection, leaving users exposed to the full scope of the flaw. The discovery highlights the security challenges of legacy serialization mechanisms, especially in .NET where binary formats were essential.
As .NET 9 deprecates binary serialization, a move by Microsoft to mitigate similar risks, Apache is now weighing removing this support from the NMS API entirely in upcoming releases. This shift aligns with broader industry trends toward more secure alternatives like JSON or Protocol Buffers, reducing the attack surface for exploits based on deserialization.
To address CVE-2025-54539, Apache recommends upgrading to version 2.4.0 or later, where the deserialization logic has been hardened against these attacks.
See also: Apache Tika: Critical Vulnerability in PDF Parser – Update now

For projects still tied to .NET binary serialization, migrating to modern formats is a necessary hardening measure. Organizations using ActiveMQ in distributed systems, such as financial services or IoT infrastructure, should prioritize patch updates to prevent lateral movement by threat actors.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
