netty-codec-mqtt is vulnerable to Improper Input Validation
35
Low Risk
The MQTT encoder writes topic names, client IDs, and other UTF-8 string fields without validating them against the MQTT 3.1.1/5.0 specification. Applications can therefore emit null bytes, wildcard characters (+, #), and control characters in these fields. This enables ACL bypass through null-byte injection, unintended topic publishing through wildcards, client-ID collisions, and log injection. The fix validates these string fields during encoding.
You are affected if you are using a version that falls within the vulnerable range and your application encodes MQTT topic names or client IDs from externally influenced input.
netty-codec-mqtt is vulnerable to Improper Input Validation in versions 0.0.1 - 4.1.136.Final and 4.2.0.Final - 4.2.16.Final.
Upgrade the io.netty:netty-codec-mqtt library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.