CVE-2024-10525: Eclipse Mosquitto

Critical severity, CVSS 9.8. EPSS: 59.5% chance of exploitation in the next 30 days.

In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bounds memory access when acting in its on_subscribe callback. This affects the mosquitto_sub and mosquitto_rr clients.

Affected products

  • Eclipse Mosquitto: from 1.3.2, before 2.0.19 (fixed in 2.0.19)

Published 2024-10-30. Last modified 2026-06-17.