CVE-2026-8686

Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a denial of service by sending a crafted packet. To remediate this issue, users should upgrade to v5.0.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:freertos:coremqtt:5.0.0:*:*:*:*:*:*:*

History

19 May 2026, 14:01

Type Values Removed Values Added
CPE cpe:2.3:a:freertos:coremqtt:5.0.0:*:*:*:*:*:*:*
First Time Freertos coremqtt
Freertos
References () https://aws.amazon.com/security/security-bulletins/2026-032-aws/ - () https://aws.amazon.com/security/security-bulletins/2026-032-aws/ - Vendor Advisory
References () https://github.com/FreeRTOS/coreMQTT/releases/tag/v5.0.1 - () https://github.com/FreeRTOS/coreMQTT/releases/tag/v5.0.1 - Release Notes
References () https://github.com/FreeRTOS/coreMQTT/security/advisories/GHSA-6qh9-r6jp-2wxc - () https://github.com/FreeRTOS/coreMQTT/security/advisories/GHSA-6qh9-r6jp-2wxc - Vendor Advisory

15 May 2026, 19:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-15 19:17

Updated : 2026-05-19 14:01


NVD link : CVE-2026-8686

Mitre link : CVE-2026-8686

CVE.ORG link : CVE-2026-8686


JSON object : View

Products Affected

freertos

  • coremqtt
CWE
CWE-125

Out-of-bounds Read