Vulnerabilities > Eclipse > Mosquitto > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-10-30 CVE-2024-10525 Out-of-bounds Write vulnerability in Eclipse Mosquitto
In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bounds memory access when acting in its on_subscribe callback.
network
low complexity
eclipse CWE-787
critical
9.8