CVE Feed

    Dashboard / CVE / CVE-2024-3935

    CVE-2024-3935

    In Eclipse Mosquito, versions from 2.0.0 through 2.0.18, if a Mosquitto broker is configured to create an outgoing bridge connection, and that bridge connection has an incoming topic configured that makes use of topic remapping, then if the remote connection sends a crafted PUBLISH packet to the broker a double free will occur with a subsequent crash of the broker.

    Published:Oct 30, 2024
    Last Modified:Nov 3, 2025
    EPS:Oct 30, 2024
    EPSS Score:0.00685
    CVSS Score:6.5

    Affected Products

    Vendor
    Eclipse
    Product
    Mosquitto
    Vendor
    Eclipse Foundation
    Product
    Mosquitto

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High