Vulnerabilities/

Denial of Service in mqtt (GHSA-h9mj-fghc-664w)

Severity:
Medium

Description

Affected versions of mqtt do not properly handle PUBLISH packets returning from the server, leading to a Denial of Service condition.

The vulnerability is completely mitigated if the only connected servers are trusted, guaranteed not to be under the control of a malicious actor.

Recommendation

Update the mqtt package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
mqtt
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing