VDB
Sign up
HIGH

GHSA-g3r2-65gc-qpqc

Denial of Service in mqtt-packet

Quick fix

GHSA-g3r2-65gc-qpqc — mqtt-packet: upgrade to the fixed version with the command below.

npm install mqtt-packet@3.4.6

Details

Versions of `mqtt-packet` prior to 3.4.6, or 4.x prior to 4.0.5 are affected by a denial of service vulnerability wherein specific sequences of MQTT packets can crash the application.

## Recommendation

Version 3.x: Update to version 3.4.6 or later. Version 4.x: Update to version 4.0.5 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/mqtt-packet
Introduced in: 0Fixed in: 3.4.6
Fixnpm install mqtt-packet@3.4.6
npm/mqtt-packet
Introduced in: 4.0.0Fixed in: 4.0.5
Fixnpm install mqtt-packet@4.0.5

References