CVE-2021-41039: High severity tibco messaging - eclipse mosquitto distribution - core vulnerability
In versions 1.6 to 2.0.11 of Eclipse Mosquitto, an MQTT v5 client connecting with a large number of user-property properties could cause excessive CPU usage, leading to a loss of performance and possible denial of service.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-41039?
CVE-2021-41039 is a vulnerability in versions 1.6 to 2.0.11 of Eclipse Mosquitto that can cause excessive CPU usage and lead to a loss of performance and possible denial of service when an MQTT v5 client connects with a large number of user-property properties.
How does CVE-2021-41039 affect Eclipse Mosquitto?
CVE-2021-41039 affects versions 1.6 to 2.0.11 of Eclipse Mosquitto by causing excessive CPU usage, which can result in a loss of performance and possible denial of service.
What is the severity of CVE-2021-41039?
CVE-2021-41039 has a severity rating of 7.5 (high).
How can I fix CVE-2021-41039 in Eclipse Mosquitto?
To fix CVE-2021-41039, you should update Eclipse Mosquitto to a version that is not affected, such as version 2.0.18.
Where can I find more information about CVE-2021-41039?
You can find more information about CVE-2021-41039 on the Eclipse Bugzilla website (https://bugs.eclipse.org/bugs/show_bug.cgi?id=575314) and the Debian Security tracker (https://security-tracker.debian.org/tracker/CVE-2021-34434).