Mosquitto

Vendor:

First CVE: Jun 25, 2017 · Active for 9 years

26
Total CVEs
More Total CVEs than 95% of tracked products
4.3
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 41% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Mosquitto over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 25, 2017
9 years ago
Most Recent CVE
Oct 30, 2024
633 days ago

CVE Severity & Scoring

Mosquitto26 CVEs
All CVEs352,427 CVEs
MediumHighCritical
Attack Vector
Local1 (3.8%)
Network25 (96.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (84.6%)
High4 (15.4%)
Unknown0 (0.0%)
User Interaction
None26 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low10 (38.5%)
High0 (0.0%)
None16 (61.5%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bound
Oct 30, 20249.860NONO
In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting with $, but that is not $SYS, e.g. $test/test, then an assert
Nov 15, 20187.543NONO
In Eclipse Mosquitto versions 2.0.7 and earlier, the server will crash if the client tries to send a PUBLISH packet with topic length = 0.
Jul 27, 20217.527NONO
In Eclipse Mosquitto 1.4.14, a user can shutdown the Mosquitto server simply by filling the RAM memory with a lot of connections with large payload. This can be done without authen
Apr 24, 20187.526NONO
In Eclipse Mosquitto version from 1.0 to 1.4.15, a Null Dereference vulnerability was found in the Mosquitto library which could lead to crashes for those applications using the li
Mar 27, 20197.525NONO
When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use a password file for authentication, any malformed data in the password file will be treated as valid. T
Mar 27, 20198.125NONO
When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use an ACL file, and that ACL file is empty, or contains only comments or blank lines, then Mosquitto will
Mar 27, 20198.125NONO
In Mosquitto before 2.0.16, a memory leak occurs when clients send v5 CONNECT packets with a will message that contains invalid property types.
Oct 2, 20237.524NONO
In versions 1.6 to 2.0.11 of Eclipse Mosquitto, an MQTT v5 client connecting with a large number of user-property properties could cause excessive CPU usage, leading to a loss of p
Dec 1, 20217.524NONO
Eclipse Mosquitto 1.5.x before 1.5.5 allows ACL bypass: if the option per_listener_settings was set to true, and the default listener was in use, and the default listener specified
Dec 13, 20187.524NONO

Exploit Exposure

Signals from CVEs in this product scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (26 CVEs).

Media Mentions

Signals from CVEs in this product scope (26 CVEs).

Top CNAs Publishing CVEs For Mosquitto

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.0.517.50.7%00