mqtt-packet@4.0.5 vulnerabilities

Parse and generate MQTT packets like a breeze

Direct Vulnerabilities

Known vulnerabilities in the mqtt-packet package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Buffer Over-read

mqtt-packet is an Encoder and Decoder for MQTT.

Affected versions of this package are vulnerable to Buffer Over-read. An attacker could trigger an out of range read on a buffer which throws a RangeError. MQTT Brokers using this module could be forced to crash by sending a specifically malformed MQTT Subscribe packet.

How to fix Buffer Over-read?

Upgrade mqtt-packet to version 3.5.1, 4.1.3, 5.6.1, 6.1.2 or higher.

<3.5.1 >=4.0.0 <4.1.3 >=5.0.0 <5.6.1 >=6.0.0 <6.1.2