CVE-2025-29953

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Apr 18, 2025
Updated: Apr 23, 2025
CWE ID 502

Summary

CVE-2025-29953 is a Deserialization of Untrusted Data vulnerability affecting Apache ActiveMQ NMS OpenWire Client before version 2.1.1. This issue arises when the client performs connections to untrusted servers, allowing these servers to provide malicious responses that may lead to arbitrary code execution on the client. The introduction of an allow/denylist feature in version 2.1.0 to restrict deserialization can be bypassed. Additionally, the .NET team has deprecated the built-in .NET binary serialization feature and recommends migrating away from it. Users should upgrade to version 2.1.1 to address the vulnerability and consider alternative methods for securing their applications.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share