Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a denial of service by sending a crafted packet.
To remediate this issue, users should upgrade to v5.0.1.
Metrics
Affected Vendors & Products
References
History
Fri, 15 May 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 15 May 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a denial of service by sending a crafted packet. To remediate this issue, users should upgrade to v5.0.1. | |
| Title | DoS from MQTT v5.0 Deserialization Fault in core MQTT | |
| First Time appeared |
Freertos
Freertos coremqtt |
|
| Weaknesses | CWE-125 | |
| CPEs | cpe:2.3:a:freertos:coremqtt:5.0.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Freertos
Freertos coremqtt |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published: 2026-05-15T18:38:10.651Z
Updated: 2026-05-15T20:22:58.148Z
Reserved: 2026-05-15T14:25:50.894Z
Link: CVE-2026-8686
Updated: 2026-05-15T20:22:54.887Z
Status : Received
Published: 2026-05-15T19:17:05.057
Modified: 2026-05-15T19:17:05.057
Link: CVE-2026-8686
No data.
ReportizFlow