CVE-2023-5632

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/10/2023
Last modified:
25/06/2025

Description

In Eclipse Mosquito before and including 2.0.5, establishing a connection to the mosquitto server without sending data causes the EPOLLOUT event to be added, which results excessive CPU consumption. This could be used by a malicious actor to perform denial of service type attack. This issue is fixed in 2.0.6<br /> <br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:eclipse:mosquitto:2.0.5:*:*:*:*:*:*:*