Vulnerability record · CVE-2024-10525 · published 30 October 2024
CVE-2024-10525: Eclipse Mosquitto libmosquitto out-of-bounds write via crafted SUBACK
Eclipse · Mosquitto
In Eclipse Mosquitto versions 1.3.2 through 2.0.18, a malicious broker can send a crafted SUBACK packet with no reason codes, causing libmosquitto clients to perform out-of-bounds memory access in the on_subscribe callback. The flaw is a heap-based buffer overflow and out-of-bounds write affecting the mosquitto_sub and mosquitto_rr clients. It matters because a client connecting to an untrusted or compromised broker can be crashed or corrupted with attacker-influenced memory writes.
Description
In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bounds memory access when acting in its on_subscribe callback. This affects the mosquitto_sub and mosquitto_rr clients.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
high priorityCVSS 4.0 score of 7.2 with high EPSS and an exploit-tagged reference, though no KEV listing or confirmed in-the-wild exploitation.
What it is
In Eclipse Mosquitto versions 1.3.2 through 2.0.18, a malicious broker can send a crafted SUBACK packet with no reason codes, causing libmosquitto clients to perform out-of-bounds memory access in the on_subscribe callback. The flaw is a heap-based buffer overflow and out-of-bounds write affecting the mosquitto_sub and mosquitto_rr clients. It matters because a client connecting to an untrusted or compromised broker can be crashed or corrupted with attacker-influenced memory writes.
Impact
An attacker controlling the broker gains the ability to trigger out-of-bounds writes in the connecting client process, which can crash it and potentially lead to memory corruption or code execution in the client context.
Attack surface
Reached over the network when a libmosquitto-based client connects to a malicious or compromised MQTT broker; the CVSS vector indicates network attack with low privileges required and no user interaction.
Exploitation
Not listed in CISA KEV and no ransomware association is documented, but EPSS is high at roughly 0.59 (99th percentile) and a reference is tagged Exploit, indicating public exploit interest.
What to do
- Upgrade Eclipse Mosquitto to version 2.0.19 or later, which contains the patch commit.
- Apply the vendor patch commit 8ab20b4ba4204fdcdec78cb4d9f03c944a6e0e1c if upgrading is not immediately possible.
- Restrict mosquitto_sub and mosquitto_rr clients to connecting only to trusted, authenticated brokers.
- Use TLS with broker certificate validation so clients do not connect to spoofed or untrusted brokers.
- Track Debian LTS advisories for backported fixes if running distribution-packaged Mosquitto.
Detection
- Monitor client processes for crashes or abnormal termination when connecting to brokers, especially mosquitto_sub and mosquitto_rr.
- Inspect MQTT SUBACK packets for missing reason codes on connections to untrusted brokers.
- Watch for unexpected broker endpoints or certificate mismatches in client connection logs.
- Correlate client-side memory error reports (ASAN, core dumps) with MQTT broker connections.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-10525 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-10525), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.