vulnerability
Ubuntu: USN-6492-1 (CVE-2021-34431): Mosquitto vulnerabilities
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 4 | (AV:N/AC:L/Au:S/C:N/I:N/A:P) | Jul 22, 2021 | Nov 22, 2023 | Aug 18, 2025 |
Severity
4
CVSS
(AV:N/AC:L/Au:S/C:N/I:N/A:P)
Published
Jul 22, 2021
Added
Nov 22, 2023
Modified
Aug 18, 2025
Description
In Eclipse Mosquitto version 1.6 to 2.0.10, if an authenticated client that had connected with MQTT v5 sent a crafted CONNECT message to the broker a memory leak would occur, which could be used to provide a DoS attack against the broker.
Solution
ubuntu-pro-upgrade-mosquitto
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.