Intel

AIKIDO-2026-182097

mqtt is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)GHSA-c8jq-r765-cq7g Published 4 days ago

85

High Risk

This Affects:

JSmqtt
0.0.1 - 5.15.2
Fixed in 5.16.0
Are you affected? Scan for Free

TL;DR

MQTT.js's MQTT 5 packet handlers accepted broker-controlled AUTH, Topic Alias, and SUBACK packets without validating protocol state, causing crashes, session state corruption, and an uncaught TypeError. connect() also mutated the caller's properties object, while QoS 2 messages awaiting PUBREL could accumulate without limit. Six GHSA advisories were fixed in v5.16.0: GHSA-8phv-jwjm-93rr, GHSA-c8jq-r765-cq7g, GHSA-fwrw-4mhv-wxvm, GHSA-gfxc-3w7m-8ch4, GHSA-h8jm-hm87-fqw3, and GHSA-rj8f-4655-cgg2.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you connect the client to an MQTT broker that is not fully trusted or could be compromised.

Background info

mqtt is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 5.15.2.

How to fix this

Upgrade the mqtt library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform