In Eclipse Mosquito before and including 2.0.5, establishing a connection to the mosquitto server without sending data causes the EPOLLOUT event to be added, which results excessive CPU consumption. This could be used by a malicious actor to perform denial of service type attack. This issue is fixed in 2.0.6
                
            References
                    Configurations
                    History
                    25 Jun 2025, 20:53
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:eclipse:mosquitto:2.0.5:*:*:*:*:*:*:* | 
21 Nov 2024, 08:42
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://github.com/eclipse/mosquitto/commit/18bad1ff32435e523d7507e9b2ce0010124a8f2d - Patch | |
| References | () https://github.com/eclipse/mosquitto/pull/2053 - Issue Tracking | 
25 Oct 2023, 17:32
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | v2 : v3 : | v2 : unknown v3 : 7.5 | 
| CPE | cpe:2.3:a:eclipse:mosquitto:*:*:*:*:*:*:*:* | |
| References | (MISC) https://github.com/eclipse/mosquitto/pull/2053 - Issue Tracking | |
| References | (MISC) https://github.com/eclipse/mosquitto/commit/18bad1ff32435e523d7507e9b2ce0010124a8f2d - Patch | |
| First Time | Eclipse mosquitto Eclipse | |
| CWE | CWE-834 | 
18 Oct 2023, 09:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2023-10-18 09:15
Updated : 2025-06-25 20:53
NVD link : CVE-2023-5632
Mitre link : CVE-2023-5632
CVE.ORG link : CVE-2023-5632
JSON object : View
Products Affected
                eclipse
- mosquitto
CWE
                
                    
                        
                        CWE-834
                        
            Excessive Iteration
