Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a denial of service by sending a crafted packet.
To remediate this issue, users should upgrade to v5.0.1.
To remediate this issue, users should upgrade to v5.0.1.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 15 May 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a denial of service by sending a crafted packet. To remediate this issue, users should upgrade to v5.0.1. | |
| Title | DoS from MQTT v5.0 Deserialization Fault in core MQTT | |
| First Time appeared |
Freertos
Freertos coremqtt |
|
| Weaknesses | CWE-125 | |
| CPEs | cpe:2.3:a:freertos:coremqtt:5.0.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Freertos
Freertos coremqtt |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-05-15T20:22:58.148Z
Reserved: 2026-05-15T14:25:50.894Z
Link: CVE-2026-8686
No data.
Status : Received
Published: 2026-05-15T19:17:05.057
Modified: 2026-05-15T19:17:05.057
Link: CVE-2026-8686
No data.
OpenCVE Enrichment
No data.
Weaknesses