Eclipse Mosquitto

Eclipse · 16 CVEs

CVE-2021-41039
HIGH

In versions 1.6 to 2.0.11 of Eclipse Mosquitto, an MQTT v5 client connecting with a large number of user-property prope…

Dec 1, 2021

CVE-2021-34434
MEDIUM

In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to mak…

Aug 30, 2021

CVE-2021-34432
HIGH

In Eclipse Mosquitto versions 2.0.7 and earlier, the server will crash if the client tries to send a PUBLISH packet wit…

Jul 27, 2021

CVE-2021-34431
MEDIUM

In Eclipse Mosquitto version 1.6 to 2.0.10, if an authenticated client that had connected with MQTT v5 sent a crafted C…

Jul 22, 2021

CVE-2021-28166
MEDIUM

In Eclipse Mosquitto version 2.0.0 to 2.0.9, if an authenticated client that had connected with MQTT v5 sent a crafted…

Apr 7, 2021

CVE-2019-11779
MEDIUM

In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic t…

Sep 19, 2019

CVE-2019-11778
MEDIUM

If an MQTT v5 client connects to Eclipse Mosquitto versions 1.6.0 to 1.6.4 inclusive, sets a last will and testament, s…

Sep 18, 2019

CVE-2017-7655
HIGH

In Eclipse Mosquitto version from 1.0 to 1.4.15, a Null Dereference vulnerability was found in the Mosquitto library wh…

Mar 27, 2019

CVE-2018-12551
HIGH

When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use a password file for authentication, any ma…

Mar 27, 2019

CVE-2018-12550
HIGH

When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use an ACL file, and that ACL file is empty, o…

Mar 27, 2019

CVE-2018-12546
MEDIUM

In Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) when a client publishes a retained message to a topic, then has i…

Mar 27, 2019

CVE-2018-12543
HIGH

In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting…

Nov 15, 2018

CVE-2017-7654
HIGH

In Eclipse Mosquitto 1.4.15 and earlier, a Memory Leak vulnerability was found within the Mosquitto Broker. Unauthentic…

Jun 5, 2018

CVE-2017-7653
MEDIUM

The Eclipse Mosquitto broker up to version 1.4.15 does not reject strings that are not valid UTF-8. A malicious client…

Jun 5, 2018

CVE-2017-7652
HIGH

In Eclipse Mosquitto 1.4.14, if a Mosquitto instance is set running with a configuration file, then sending a HUP signa…

Apr 25, 2018

CVE-2017-7651
HIGH

In Eclipse Mosquitto 1.4.14, a user can shutdown the Mosquitto server simply by filling the RAM memory with a lot of co…

Apr 24, 2018

Showing 1 to 16 of 16 CVEs