Description
In Eclipse Mosquito before and including 2.0.5, establishing a connection to the mosquitto server without sending data causes the EPOLLOUT event to be added, which results excessive CPU consumption. This could be used by a malicious actor to perform denial of service type attack. This issue is fixed in 2.0.6
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-57925 | In Eclipse Mosquito before and including 2.0.5, establishing a connection to the mosquitto server without sending data causes the EPOLLOUT event to be added, which results excessive CPU consumption. This could be used by a malicious actor to perform denial of service type attack. This issue is fixed in 2.0.6 |
References
History
Wed, 25 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:eclipse:mosquitto:2.0.5:*:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2024-09-13T14:50:24.704Z
Reserved: 2023-10-18T08:17:55.102Z
Link: CVE-2023-5632
Updated: 2024-08-02T08:07:32.289Z
Status : Analyzed
Published: 2023-10-18T09:15:10.080
Modified: 2025-06-25T20:53:55.653
Link: CVE-2023-5632
OpenCVE Enrichment
No data.
Weaknesses
EUVD