CVE-2025-29953 - CVE House
Back to Database
Status published Unknown CVE-2025-29953

Apache ActiveMQ NMS OpenWire Client: deserialization allowlist bypass

Vulnerability Description

Deserialization of Untrusted Data vulnerability in Apache ActiveMQ NMS OpenWire Client. This issue affects Apache ActiveMQ NMS OpenWire Client before 2.1.1 when performing connections to untrusted servers. Such servers could abuse the unbounded deserialization in the client to provide malicious responses that may eventually cause arbitrary code execution on the client. Version 2.1.0 introduced a allow/denylist feature to restrict deserialization, but this feature could be bypassed. The .NET team has deprecated the built-in .NET binary serialization feature starting with .NET 9 and suggests migrating away from binary serialization. The project is considering to follow suit and drop this part of the NMS API altogether. Users are recommended to upgrade to version 2.1.1, which fixes the issue. We also recommend to migrate away from relying on .NET binary serialization as a hardening method for the future.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-29953

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • g7shot working with Trend Zero Day Initiative

Affected Vendor

Apache Software Foundation

View all reports →

Affected Software

Apache ActiveMQ NMS OpenWire Client
Vulnerable Versions:
0

Timeline

Official Publish: April 18th, 2025
Last Modified: April 23rd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)