CVE-2026-8686

Source
https://cve.org/CVERecord?id=CVE-2026-8686
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-8686.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-8686
Aliases
  • GHSA-6qh9-r6jp-2wxc
Published
2026-05-15T18:38:10.651Z
Modified
2026-08-04T11:51:21.987778885Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
DoS from MQTT v5.0 Deserialization Fault in core MQTT
Details

Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a denial of service by sending a crafted packet.

To remediate this issue, users should upgrade to v5.0.1.

Database specific
{
    "cwe_ids": [
        "CWE-125"
    ],
    "cna_assigner": "AMZN",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8686.json"
}
References

Affected packages

Git / github.com/freertos/coremqtt

Affected ranges

Type
GIT
Repo
https://github.com/freertos/coremqtt
Events
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "5.0.0"
        },
        {
            "last_affected": "5.0.0"
        }
    ]
}

Affected versions

5.*
5.0.0
v5.*
v5.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-8686.json"