High severity7.5NVD Advisory· Published May 31, 2018· Updated Jun 17, 2026
CVE-2016-10523
CVE-2016-10523
Description
MQTT before 3.4.6 and 4.0.x before 4.0.5 allows specifically crafted MQTT packets to crash the application, making a DoS attack feasible with very little bandwidth.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mqtt-packetnpm | < 3.4.6 | 3.4.6 |
mqtt-packetnpm | >= 4.0.0, < 4.0.5 | 4.0.5 |
Affected products
3- cpe:2.3:a:mqtt-packet_project:mqtt-packet:*:*:*:*:*:node.js:*:*Range: <3.4.6
- HackerOne/mqtt-packet node modulev5Range: <3.4.6 || > 4.0.0 <4.0.5
Patches
Vulnerability mechanics
References
6- github.com/mcollina/mosca/issues/393nvdExploitThird Party AdvisoryWEB
- github.com/mqttjs/mqtt-packet/pull/8nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-g3r2-65gc-qpqcghsaADVISORY
- nodesecurity.io/advisories/75nvdThird Party Advisory
- nvd.nist.gov/vuln/detail/CVE-2016-10523ghsaADVISORY
- www.npmjs.com/advisories/75ghsaWEB
News mentions
0No linked articles in our index yet.