CVE-2023-0809: Eclipse Mosquitto

Medium severity, CVSS 5.3. EPSS: 0.7% chance of exploitation in the next 30 days.

In Mosquitto before 2.0.16, excessive memory is allocated based on malicious initial packets that are not CONNECT packets.

Affected products

  • Eclipse Mosquitto: before 2.0.16 (fixed in 2.0.16)

Published 2023-10-02. Last modified 2026-06-17.