RHSA-2025:17567HighCVSS 7.5

Red Hat Security Advisory: Red Hat AMQ Broker 7.13.2 release and security update

Published
October 8, 2025
Last Modified
August 2, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2025-5115 — jetty: HTTP/2 (including DNS over HTTPS) contains a design flaw and is vulnerable to "MadeYouReset" DoS attack through HTTP/2 control frames CVE-2025-27533 — ActiveMQ: ActiveMQ: Unvalidated Buffer Size Allocation CVE-2025-58056 — netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions

🎯 Affected products1

  • Red Hat AMQ Broker 7.13.2

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings. The References section of this erratum contains a download link (you must log in to download the update). Workaround: No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability. Workaround: To mitigate this issue, enforce strict RFC compliance on all front-end proxies and load balancers so that lone LF characters in chunk extensions are rejected or normalized before being forwarded. Additionally, configure input validation at the application or proxy layer to block malformed chunked requests, ensuring consistent parsing across all components in the request path.

🔗 References (18)