Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 08 Aug 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Resource Leak in CONNECT Packet Handling Leading to Denial of Service | codepr sol: Sol: Denial of service via resource exhaustion from malformed CONNECT packets |
| Weaknesses | CWE-772 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 07 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Resource Leak in CONNECT Packet Handling Leading to Denial of Service |
Fri, 07 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-400 | |
| Metrics |
cvssV3_1
|
Fri, 07 Aug 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CONNECT packets. When clients send invalid CONNECT packets - either due to repeated attempts or failed authentication - the server may silently drop the connection or send a CONNACK but fail to close the session or deallocate internal resources. This behavior allows an attacker to create numerous half-open connections that consume memory and file descriptors indefinitely, potentially triggering the Linux OOM killer and causing a denial of service. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-07T19:13:19.127Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-63235
Updated: 2026-08-07T19:11:41.262Z
No data.
OpenCVE Enrichment
Updated: 2026-08-08T02:30:04Z