CVE-2026-8686: DoS from MQTT v5.0 Deserialization Fault in core MQTT
Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a denial of service by sending a crafted packet.
To remediate this issue, users should upgrade to v5.0.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
coreMQTTto a version that resolves this vulnerability.Fixed in 5.0.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8686?
CVE-2026-8686 is categorized as a denial of service vulnerability in the MQTT v5.0 property parser.
How do I fix CVE-2026-8686?
To remediate CVE-2026-8686, users should upgrade coreMQTT to version 5.0.1 or later.
What causes the vulnerability CVE-2026-8686?
CVE-2026-8686 is caused by missing bounds validation in the MQTT v5.0 property parser.
Which software is affected by CVE-2026-8686?
CVE-2026-8686 affects Amazon coreMQTT versions prior to 5.0.1.
What kind of attack can CVE-2026-8686 lead to?
CVE-2026-8686 can lead to a denial of service attack if an MQTT broker receives a crafted packet.