Zeromq is a messaging library used throughout distributed systems and embedded applications to manage asynchronous communication, and despite its narrow product footprint, sits as a dependency in a wide range of networked software. Vulnerabilities affecting the library skew strongly toward critical severity and recur through memory-safety and resource-handling weakness classes including out-of-bounds writes, buffer overflows, and uncontrolled resource consumption, reflecting the parsing and state-management demands of a protocol-handling library. Defenders should inventory applications and systems that link this library and track its releases closely, as remediation often depends on downstream vendors recompiling; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zeromq over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-13132CRITICAL In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated client connecting to a libzmq application, running with a socket listening with | Jul 10, 2019 | 9.8 | 54 | NO | NO |
CVE-2021-20235HIGH There's a flaw in the zeromq server in versions before 4.3.3 in src/decoder_allocators.hpp. The decoder static allocator could have its sized changed, but the buffer would remain t | Apr 1, 2021 | 8.1 | 49 | NO | NO |
CVE-2021-20236CRITICAL A flaw was found in the ZeroMQ server in versions before 4.3.3. This flaw allows a malicious client to cause a stack buffer overflow on the server by sending crafted topic subscrip | May 28, 2021 | 9.8 | 30 | NO | NO |
CVE-2019-6250HIGH A pointer overflow, with code execution, was discovered in ZeroMQ libzmq (aka 0MQ) 4.2.x and 4.3.x before 4.3.1. A v2_decoder.cpp zmq::v2_decoder_t::size_ready integer overflow all | Jan 13, 2019 | 8.8 | 29 | NO | NO |
CVE-2021-20237HIGH An uncontrolled resource consumption (memory leak) flaw was found in ZeroMQ's src/xpub.cpp in versions before 4.3.3. This flaw allows a remote unauthenticated attacker to send craf | May 28, 2021 | 7.5 | 25 | NO | NO |
CVE-2020-36400CRITICAL ZeroMQ libzmq 4.3.3 has a heap-based buffer overflow in zmq::tcp_read, a different vulnerability than CVE-2021-20235. | Jul 1, 2021 | 9.8 | 24 | NO | NO |
CVE-2021-20234MEDIUM An uncontrolled resource consumption (memory leak) flaw was found in the ZeroMQ client in versions before 4.3.3 in src/pipe.cpp. This issue causes a client that connects to multipl | Apr 1, 2021 | 6.5 | 22 | NO | NO |
CVE-2020-15166HIGH In ZeroMQ before version 4.3.3, there is a denial-of-service vulnerability. Users with TCP transport public endpoints, even with CURVE/ZAP enabled, are impacted. If a raw TCP socke | Sep 11, 2020 | 7.5 | 20 | NO | NO |
CVE-2014-9721MEDIUM libzmq before 4.0.6 and 4.1.x before 4.1.1 allows remote attackers to conduct downgrade attacks and bypass ZMTP v3 protocol security mechanisms via a ZMTP v2 or earlier header. | Jun 3, 2015 | 4.3 | 14 | NO | NO |
CVE-2014-7203MEDIUM libzmq (aka ZeroMQ/C++) 4.0.x before 4.0.5 does not ensure that nonces are unique, which allows man-in-the-middle attackers to conduct replay attacks via unspecified vectors. | Oct 8, 2014 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zeromq.
Media articles that mention a CVE ID that affects a product developed by Zeromq — matched by CVE ID, not by vendor name.