CVE-2025-65503: Redboltz Async Mqtt

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Use after free in endpoint destructors in Redboltz async_mqtt 10.2.5 allows local users to cause a denial of service via triggering SSL initialization failure that results in incorrect destruction order between io_context and endpoint objects.

Affected products

  • Redboltz Async Mqtt: version 10.2.5 only

Published 2025-11-24. Last modified 2026-06-17.