CVE-2024-10525: Eclipse Mosquitto
Critical severity, CVSS 9.8. EPSS: 59.5% chance of exploitation in the next 30 days.
In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bounds memory access when acting in its on_subscribe callback. This affects the mosquitto_sub and mosquitto_rr clients.
Affected products
- Eclipse Mosquitto: from 1.3.2, before 2.0.19 (fixed in 2.0.19)
Published 2024-10-30. Last modified 2026-06-17.