Intel

AIKIDO-2025-10726

github.com/eclipse/paho.mqtt.golang is vulnerable to Integer Overflow

Integer OverflowCVE-2025-10543 Published Oct 21, 2025

53

Medium Risk

This Affects:

GOgithub.com/eclipse/paho.mqtt.golang
0.9.0 - 1.5.0
Fixed in 1.5.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to an Integer Overflow when processing UTF-8 strings longer than 65535 bytes, causing incorrect encoding and potential data leakage between MQTT packet fields. Attackers can exploit this to corrupt packets or inject unexpected data into message bodies.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/eclipse/paho.mqtt.golang is vulnerable to Integer Overflow in versions 0.9.0 - 1.5.0.

How to fix this

Upgrade the github.com/eclipse/paho.mqtt.golang library to the patch version.