CVE-2026-8686

Severity CVSS v4.0:
HIGH
Type:
CWE-125 Out-of-bounds Read
Publication date:
15/05/2026
Last modified:
15/05/2026

Description

Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a denial of service by sending a crafted packet.<br /> <br /> <br /> <br /> To remediate this issue, users should upgrade to v5.0.1.