← Vulnerability feed

Vulnerability record · CVE-2024-10525 · published 30 October 2024

CVE-2024-10525: Eclipse Mosquitto libmosquitto out-of-bounds write via crafted SUBACK

Eclipse · Mosquitto

In Eclipse Mosquitto versions 1.3.2 through 2.0.18, a malicious broker can send a crafted SUBACK packet with no reason codes, causing libmosquitto clients to perform out-of-bounds memory access in the on_subscribe callback. The flaw is a heap-based buffer overflow and out-of-bounds write affecting the mosquitto_sub and mosquitto_rr clients. It matters because a client connecting to an untrusted or compromised broker can be crashed or corrupted with attacker-influenced memory writes.

7.2 CVSS 4.0 High EPSS 59% · top 0.9% CWE-122 · Heap-based buffer overflowCWE-787 · Out-of-bounds write
7.2CVSS 4.0 base score
59%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bounds memory access when acting in its on_subscribe callback. This affects the mosquitto_sub and mosquitto_rr clients.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityCVSS 4.0 score of 7.2 with high EPSS and an exploit-tagged reference, though no KEV listing or confirmed in-the-wild exploitation.

What it is

In Eclipse Mosquitto versions 1.3.2 through 2.0.18, a malicious broker can send a crafted SUBACK packet with no reason codes, causing libmosquitto clients to perform out-of-bounds memory access in the on_subscribe callback. The flaw is a heap-based buffer overflow and out-of-bounds write affecting the mosquitto_sub and mosquitto_rr clients. It matters because a client connecting to an untrusted or compromised broker can be crashed or corrupted with attacker-influenced memory writes.

Impact

An attacker controlling the broker gains the ability to trigger out-of-bounds writes in the connecting client process, which can crash it and potentially lead to memory corruption or code execution in the client context.

Attack surface

Reached over the network when a libmosquitto-based client connects to a malicious or compromised MQTT broker; the CVSS vector indicates network attack with low privileges required and no user interaction.

Exploitation

Not listed in CISA KEV and no ransomware association is documented, but EPSS is high at roughly 0.59 (99th percentile) and a reference is tagged Exploit, indicating public exploit interest.

What to do

  • Upgrade Eclipse Mosquitto to version 2.0.19 or later, which contains the patch commit.
  • Apply the vendor patch commit 8ab20b4ba4204fdcdec78cb4d9f03c944a6e0e1c if upgrading is not immediately possible.
  • Restrict mosquitto_sub and mosquitto_rr clients to connecting only to trusted, authenticated brokers.
  • Use TLS with broker certificate validation so clients do not connect to spoofed or untrusted brokers.
  • Track Debian LTS advisories for backported fixes if running distribution-packaged Mosquitto.

Detection

  • Monitor client processes for crashes or abnormal termination when connecting to brokers, especially mosquitto_sub and mosquitto_rr.
  • Inspect MQTT SUBACK packets for missing reason codes on connections to untrusted brokers.
  • Watch for unexpected broker endpoints or certificate mismatches in client connection logs.
  • Correlate client-side memory error reports (ASAN, core dumps) with MQTT broker connections.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-10525 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2018-12550Eclipse mosquitto vulnerabilityWhen Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use an ACL file, and that ACL file is empty, or contains only comments or bl…EPSS 1.4%8.1CVE-2018-12551Eclipse mosquitto improper authentication vulnerabilityWhen Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use a password file for authentication, any malformed data in the password f…EPSS 1.5%7.5CVE-2023-5632Eclipse mosquitto vulnerabilityIn Eclipse Mosquito before and including 2.0.5, establishing a connection to the mosquitto server without sending data causes the EPOLLOUT event to b…EPSS 0.69%7.5CVE-2023-3592Eclipse mosquitto memory leak vulnerabilityIn Mosquitto before 2.0.16, a memory leak occurs when clients send v5 CONNECT packets with a will message that contains invalid property types.EPSS 0.79%7.5CVE-2023-28366Eclipse mosquitto memory leak vulnerabilityThe broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages…EPSS 1.3%7.5CVE-2021-41039Eclipse mosquitto vulnerabilityIn versions 1.6 to 2.0.11 of Eclipse Mosquitto, an MQTT v5 client connecting with a large number of user-property properties could cause excessive CP…EPSS 1.4%7.5CVE-2021-34432Eclipse mosquitto improper input validation vulnerabilityIn Eclipse Mosquitto versions 2.0.7 and earlier, the server will crash if the client tries to send a PUBLISH packet with topic length = 0.EPSS 1.2%7.5CVE-2017-7655Eclipse mosquitto null pointer dereference vulnerabilityIn Eclipse Mosquitto version from 1.0 to 1.4.15, a Null Dereference vulnerability was found in the Mosquitto library which could lead to crashes for …EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2024-10525), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.