PT-2021-7060 · Eclipse+3 · Eclipse Mosquitto+3

Bin Yuan

+5

·

Published

2021-08-09

·

Updated

2025-03-10

·

CVE-2021-41039

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Eclipse Mosquitto versions 1.6 through 2.0.11
Description The issue is related to the implementation of the MQTT v5 protocol in Eclipse Mosquitto, which can cause excessive CPU usage. This can be exploited by a remote attacker to cause a denial of service. The problem occurs when an MQTT v5 client connects with a large number of user-property properties.
Recommendations For Eclipse Mosquitto versions 1.6 through 2.0.11, consider restricting the number of user-property properties that can be sent by an MQTT v5 client to prevent excessive CPU usage. As a temporary workaround, restrict access to the MQTT v5 protocol until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-4418
ALT-PU-2024-12359
ALT-PU-2025-3746
BDU:2022-03119
CVE-2021-41039
DSA-5511-1
OESA-2022-1498
ROSA-SA-2023-2224
USN-6492-1

Affected Products

Alt Linux
Eclipse Mosquitto
Linuxmint
Ubuntu