Loading HuntDB...

GHSA-897v-899r-j3hg

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages with duplicate message IDs, and fails to respond to PUBREC commands. This occurs because of mishandling of EAGAIN from the libc send function.

Related CVEs

Key Information

GHSA ID
GHSA-897v-899r-j3hg
Published
September 1, 2023 6:30 PM
Last Modified
June 26, 2025 6:31 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 9, 2025 6:37 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.