Mosquitto
Vendor:
First CVE: Jun 25, 2017 · Active for 9 years
26
Total CVEs
More Total CVEs than 95% of tracked products
4.3
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 41% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Mosquitto over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 25, 2017
9 years ago
Most Recent CVE
Oct 30, 2024
633 days ago
CVE Severity & Scoring
Mosquitto26 CVEs
42%
54%
All CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (3.8%)
Network25 (96.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (84.6%)
High4 (15.4%)
Unknown0 (0.0%)
User Interaction
None26 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low10 (38.5%)
High0 (0.0%)
None16 (61.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-10525CRITICAL In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bound | Oct 30, 2024 | 9.8 | 60 | NO | NO |
CVE-2018-12543HIGH In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting with $, but that is not $SYS, e.g. $test/test, then an assert | Nov 15, 2018 | 7.5 | 43 | NO | NO |
CVE-2021-34432HIGH In Eclipse Mosquitto versions 2.0.7 and earlier, the server will crash if the client tries to send a PUBLISH packet with topic length = 0. | Jul 27, 2021 | 7.5 | 27 | NO | NO |
CVE-2017-7651HIGH In Eclipse Mosquitto 1.4.14, a user can shutdown the Mosquitto server simply by filling the RAM memory with a lot of connections with large payload. This can be done without authen | Apr 24, 2018 | 7.5 | 26 | NO | NO |
CVE-2017-7655HIGH In Eclipse Mosquitto version from 1.0 to 1.4.15, a Null Dereference vulnerability was found in the Mosquitto library which could lead to crashes for those applications using the li | Mar 27, 2019 | 7.5 | 25 | NO | NO |
CVE-2018-12551HIGH When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use a password file for authentication, any malformed data in the password file will be treated as valid. T | Mar 27, 2019 | 8.1 | 25 | NO | NO |
CVE-2018-12550HIGH When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use an ACL file, and that ACL file is empty, or contains only comments or blank lines, then Mosquitto will | Mar 27, 2019 | 8.1 | 25 | NO | NO |
CVE-2023-3592HIGH In Mosquitto before 2.0.16, a memory leak occurs when clients send v5 CONNECT packets with a will message that contains invalid property types. | Oct 2, 2023 | 7.5 | 24 | NO | NO |
CVE-2021-41039HIGH In versions 1.6 to 2.0.11 of Eclipse Mosquitto, an MQTT v5 client connecting with a large number of user-property properties could cause excessive CPU usage, leading to a loss of p | Dec 1, 2021 | 7.5 | 24 | NO | NO |
CVE-2018-20145HIGH Eclipse Mosquitto 1.5.x before 1.5.5 allows ACL bypass: if the option per_listener_settings was set to true, and the default listener was in use, and the default listener specified | Dec 13, 2018 | 7.5 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (26 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (26 CVEs).
Media Mentions
Signals from CVEs in this product scope (26 CVEs).
Top CNAs Publishing CVEs For Mosquitto
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.0.5 | 1 | 7.5 | 0.7% | 0 | 0 |