CVE-2025-29953
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2025-29953 is a Deserialization of Untrusted Data vulnerability affecting Apache ActiveMQ NMS OpenWire Client before version 2.1.1. This issue arises when the client performs connections to untrusted servers, allowing these servers to provide malicious responses that may lead to arbitrary code execution on the client. The introduction of an allow/denylist feature in version 2.1.0 to restrict deserialization can be bypassed. Additionally, the .NET team has deprecated the built-in .NET binary serialization feature and recommends migrating away from it. Users should upgrade to version 2.1.1 to address the vulnerability and consider alternative methods for securing their applications.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.