External risk intelligence

Apache ActiveMQ NMS AMQP Untrusted Deserialization Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-54539

The vulnerability resides in a client-side library (Apache ActiveMQ NMS AMQP) used by applications to connect to AMQP servers. While it involves network communication, the attack surface is the client itself connecting to a server; public internet exposure of the client-side library in a way that allows a malicious server to trigger deserialization is uncommon compared to direct public-facing services.

Deserialization

Apache Activemq Nms Amqp

before 2.4.0

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A deserialization vulnerability in the Apache ActiveMQ NMS AMQP client could allow an untrusted server to execute arbitrary code on the client side, particularly when establishing connections. While a partial mitigation was introduced, it was found to be bypassable. The project is considering removing .NET binary serialization support entirely in future releases, aligning with broader industry trends.

  • Untrusted servers can execute code on clients.
  • Impacts client connections to AMQP servers.
  • Confirm relevance and assess potential client exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this by setting up a malicious AMQP server. When a vulnerable Apache ActiveMQ NMS AMQP client attempts to connect to this server, the server can send specially crafted data. The client's deserialization process, when handling this data, could be tricked into executing arbitrary code.

  • Attacker requires network access to the client.
  • Vulnerable client connects to a malicious server.
  • Risk of arbitrary code execution on client.

Live Threat

Current exploitation, exposure, and threat context

When connecting to untrusted AMQP servers, the Apache ActiveMQ NMS AMQP Client could be vulnerable to arbitrary code execution due to deserialization of untrusted data. This could impact the confidentiality, integrity, and availability of the client system.

  • Client system and application data.
  • Malicious AMQP server interaction.
  • Arbitrary code execution on client.

Operational Fix

Recommended remediation, mitigation, and detection steps

Given this vulnerability in the Apache ActiveMQ NMS AMQP client, application owners are primarily responsible for identifying deployments and assessing their risk, especially concerning connections to untrusted AMQP servers. The first practical step is to inventory where this client library is used, determine if it connects to external AMQP endpoints, and then prioritize remediation based on this exposure. If the client is used in applications that handle sensitive data or are exposed externally, the security team should be engaged for risk assessment and mitigation planning.

  • Own by application teams.
  • Verify untrusted AMQP server connections.
  • Plan remediation for critical deployments.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Apache ActiveMQ NMS AMQP?

It is a client library for .NET applications that facilitates messaging using the AMQP protocol. Developers use it to allow their software to send and receive messages by connecting to message brokers, which act as intermediaries for data exchange in distributed systems.

How does CVE-2025-54539 work?

This vulnerability is classified as Deserialization of Untrusted Data (CWE-502). It occurs when the software reconstructs complex data objects from a source without sufficient validation. Because the client library trusts the incoming data, a malicious server can inject harmful structures that trick the application into running unauthorized commands on the host machine.

When does this vulnerability trigger?

The flaw triggers specifically when a vulnerable client initiates a connection to a malicious AMQP server and processes its responses. It does not trigger if the client only connects to trusted, internal servers that you manage and control, nor does it affect general network traffic that does not involve this specific deserialization process.

Is my system at risk from this CVE?

Halo Surface Signal indicates that risk is unlikely for many users because the vulnerability resides in a client library. The primary concern is if your application connects to external, untrusted, or public-facing AMQP servers. Internal-only applications that do not communicate with outside message brokers have a significantly lower profile regarding this threat.

Do I need to patch CVE-2025-54539?

Yes, you should prioritize upgrading to version 2.4.0 or later, which addresses the deserialization issues. Beyond patching, evaluate your application's dependency on .NET binary serialization, as moving away from this technology is the recommended long-term strategy for hardening your environment against similar deserialization risks.

References