Re: Apache ActiveMQ: CVE-2025-66168 / CVE-2025-27533

Jean-Baptiste Onofré <[email protected]> Tue, 3 Mar 2026 22:54:41 +0100
Newsgroups gmane.comp.java.activemq.devel,gmane.comp.apache.user,gmane.comp.apache.maven.announce
Message-ID <CAB8EV3Sp472mHuzdKjYReNXO4oiy2UTZMjzyK20VQg1BbrsjAg__27690.4401181795$1772574945$gmane$org@mail.gmail.com>
--00000000000026fb25064c25c17a
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Hi,

I am currently reviewing the security advisories. I have also received
several inquiries from the community regarding the possibility of a new
5.18.x release that includes only the latest CVE fixes.

I will begin preparing that release soon.

Regards,
JB

On Tue, Mar 3, 2026 at 3:13=E2=80=AFPM Casey A. Owen via users <
[email protected]> wrote:

> Hello,
>
> Could someone please clarify why the listed CVEs are not documented in th=
e
> Apache ActiveMQ Classic Security Advisories at
> https://activemq.apache.org/components/classic/security?
>
> Thank you for your prompt attention to this matter,
>
>
> Casey Owen | Sr Applications Analyst
>
>

--00000000000026fb25064c25c17a--