CVE 7.5 HIGH

DoS from MQTT v5.0 Deserialization Fault in core MQTT_CVE-2026-8686

7.5 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Description

Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a denial of service by sending a crafted packet.



To remediate this issue, users should upgrade to v5.0.1.

Basic Information

ID CVE-2026-8686
Source AMZN
Published May 15, 2026 at 18:38

Affected Product

Vendor FreeRTOS
Product coreMQTT
Version 5.0.0
Affected Versions FreeRTOS coreMQTT 5.0.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.