MQTT represents a lightweight, publish-subscribe messaging protocol widely embedded in IoT devices, industrial control systems, and real-time applications, with a narrow but foundational product footprint. The observed vulnerability signal concentrates on resource-consumption weaknesses, reflecting the protocol's role in managing message queues and broker connections in resource-constrained environments where denial-of-service conditions pose operational risk.
The number and severity of CVEs published that impact products developed by Mqtt over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-13849HIGH The MQTT protocol 3.1.1 requires a server to set a timeout value of 1.5 times the Keep-Alive value specified by a client, which allows remote attackers to cause a denial of service | Jun 4, 2020 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mqtt.
Media articles that mention a CVE ID that affects a product developed by Mqtt — matched by CVE ID, not by vendor name.