CVE-2026-8686

Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a denial of service by sending a crafted packet. To remediate this issue, users should upgrade to v5.0.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:freertos:coremqtt:5.0.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-15 19:17

Updated : 2026-06-17 11:04


NVD link : CVE-2026-8686

Mitre link : CVE-2026-8686

CVE.ORG link : CVE-2026-8686


JSON object : View

Products Affected

freertos

  • coremqtt
CWE
CWE-125

Out-of-bounds Read