Loading HuntDB...

GHSA-72qw-2vp3-gvg9

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heap-use-after-free by sending specific sequences of "CONNECT", "DISCONNECT", "SUBSCRIBE", "UNSUBSCRIBE" and "PUBLISH" packets.

Related CVEs

Key Information

GHSA ID
GHSA-72qw-2vp3-gvg9
Published
October 11, 2024 6:32 PM
Last Modified
November 15, 2024 6:30 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 10, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.