CVE-2026-8686
Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a denial of service by sending a crafted packet. To remediate this issue, users should upgrade to v5.0.1.
- Published May 15, 2026
- CVSS 8.7 high
- 0.7% chance of exploitation in the next 30 days (EPSS)
- A fix is available
Affected software
In the news
- CVE-2026-8686 - Heap out-of-bounds read in coreMQTT MQTT5 property parsing AWS Security Bulletins ·