CVE-2023-28366

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/09/2023
Last modified:
26/06/2025

Description

The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages with duplicate message IDs, and fails to respond to PUBREC commands. This occurs because of mishandling of EAGAIN from the libc send function.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:eclipse:mosquitto:*:*:*:*:*:*:*:* 1.3.2 (including) 2.0.16 (excluding)