Numeric Truncation Error Affecting github.com/eclipse/paho.mqtt.golang/packets package, versions <1.5.1


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.06% (18th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMECLIPSEPAHOMQTTGOLANGPACKETS-14171916
  • published3 Dec 2025
  • disclosed2 Dec 2025
  • creditPaul Gerste

Introduced: 2 Dec 2025

NewCVE-2025-10543  (opens in a new tab)
CWE-197  (opens in a new tab)

How to fix?

Upgrade github.com/eclipse/paho.mqtt.golang/packets to version 1.5.1 or higher.

Overview

Affected versions of this package are vulnerable to Numeric Truncation Error due to improper conversion of string length from an int64/int32 to an int16 without checks for overflows. values in the process handling UTF-8 encoded data. An attacker can cause packet corruption or unintended data leakage between fields by submitting specially crafted input strings exceeding 65535 bytes.

CVSS Base Scores

version 4.0
version 3.1