blob: 6418bd9032ae0f66be9b99310b3e512d3c85d677 [file]
{
"schema_version": "1.3.1",
"id": "GO-2025-4173",
"modified": "0001-01-01T00:00:00Z",
"published": "0001-01-01T00:00:00Z",
"aliases": [
"CVE-2025-10543",
"GHSA-32fw-gq77-f2f2"
],
"summary": "Eclipse Paho Go MQTT may incorrectly encode strings if length exceeds 65535 bytes in github.com/eclipse/paho.mqtt.golang",
"details": "Eclipse Paho Go MQTT may incorrectly encode strings if length exceeds 65535 bytes in github.com/eclipse/paho.mqtt.golang",
"affected": [
{
"package": {
"name": "github.com/eclipse/paho.mqtt.golang",
"ecosystem": "Go"
},
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "0"
},
{
"fixed": "1.5.1"
}
]
}
],
"ecosystem_specific": {}
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/advisories/GHSA-32fw-gq77-f2f2"
},
{
"type": "WEB",
"url": "https://github.com/alpinelinux/build-server-status/commit/e3487897db32c8c3d0287643f8384a6669e93731"
},
{
"type": "WEB",
"url": "https://github.com/eclipse-paho/paho.mqtt.golang/issues/730"
},
{
"type": "WEB",
"url": "https://github.com/eclipse-paho/paho.mqtt.golang/pull/714"
},
{
"type": "WEB",
"url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/254"
}
],
"database_specific": {
"url": "https://pkg.go.dev/vuln/GO-2025-4173",
"review_status": "REVIEWED"
}
}