CVE Tools

Mosquitto

26 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Mosquitto, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.

Mosquitto CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Mosquitto CVEs per month
MonthCVEs
2024-103
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 26 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical14%
  • High1350%
  • Medium1246%

Latest CVEs

The 15 most recently published vulnerabilities affecting Mosquitto.

  1. CVE-2024-3935Eclipse Mosquito: Double free vulnerability6.5
  2. CVE-2024-10525Eclipse Mosquito: Heap Buffer Overflow in my_subscribe_callback9.8
  3. CVE-2024-8376Memory leak7.5
  4. CVE-2023-5632Unconditionally adding an event to the epoll causes excessive CPU consumption7.5
  5. CVE-2023-3592In Mosquitto before 2.0.16, a memory leak occurs when clients send v5 CONNECT packets with a will message that contains invalid property types.5.8
  6. CVE-2023-0809In Mosquitto before 2.0.16, excessive memory is allocated based on malicious initial packets that are not CONNECT packets.5.8
  7. CVE-2023-28366The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages with duplicate message IDs, and fails to respon...7.5
  8. CVE-2021-41039In versions 1.6 to 2.0.11 of Eclipse Mosquitto, an MQTT v5 client connecting with a large number of user-property properties could cause excessive CPU usage, leading to a loss of performance and po...7.5
  9. CVE-2021-34434In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make subscriptions on a topic is revoked when a durable client is offline, then e...5.3
  10. CVE-2021-34432In Eclipse Mosquitto versions 2.0.7 and earlier, the server will crash if the client tries to send a PUBLISH packet with topic length = 0.7.5
  11. CVE-2021-34431In Eclipse Mosquitto version 1.6 to 2.0.10, if an authenticated client that had connected with MQTT v5 sent a crafted CONNECT message to the broker a memory leak would occur, which could be used to...6.5
  12. CVE-2021-28166In Eclipse Mosquitto version 2.0.0 to 2.0.9, if an authenticated client that had connected with MQTT v5 sent a crafted CONNACK message to the broker, a NULL pointer dereference would occur.6.5
  13. CVE-2019-11779In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters, i.e. the topic hie...6.5
  14. CVE-2019-11778If an MQTT v5 client connects to Eclipse Mosquitto versions 1.6.0 to 1.6.4 inclusive, sets a last will and testament, sets a will delay interval, sets a session expiry interval, and the will delay ...5.4
  15. CVE-2017-7655In Eclipse Mosquitto version from 1.0 to 1.4.15, a Null Dereference vulnerability was found in the Mosquitto library which could lead to crashes for those applications using the library.7.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store