An issue was discovered in Mongoose before 6.15. The parsemqtt() function in mgmqtt.c has a critical heap-based buffer overflow.