← Back to browse · API

CVE-2024-10525

Severity
HIGH
CVSS
7.2
EPSS
0.58546
Risk score
49.29
CISA KEV
No
PoC
No
Published
2024-10-30
Modified
2025-11-03
First seen
2026-08-07
Aliases
EUVD-2024-33469, GHSA-CM54-MPRW-5279
Products
Eclipse Foundation:Mosquitto 1.3.2 ≤2.0.18
Sources
euvd EUVD-2024-33469

Description

In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bounds memory access when acting in its on_subscribe callback. This affects the mosquitto_sub and mosquitto_rr clients.

References