CVE-2026-8686 – DoS from MQTT v5.0 Deserialization Fault in core MQTT

CVE ID :CVE-2026-8686

Published : May 15, 2026, 7:17 p.m. | 50 minutes ago

Description :Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a denial of service by sending a crafted packet.

To remediate this issue, users should upgrade to v5.0.1.

Severity: 8.7 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…