VYPR
High severity7.5NVD Advisory· Published May 6, 2019· Updated Jun 17, 2026

CVE-2019-5432

CVE-2019-5432

Description

A specifically malformed MQTT Subscribe packet crashes MQTT Brokers using the mqtt-packet module versions < 3.5.1, 4.0.0 - 4.1.3, 5.0.0 - 5.6.1, 6.0.0 - 6.1.2 for decoding.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
mqtt-packetnpm
< 3.5.13.5.1
mqtt-packetnpm
>= 4.0.0, < 4.1.34.1.3
mqtt-packetnpm
>= 5.0.0, < 5.6.15.6.1
mqtt-packetnpm
>= 6.0.0, < 6.1.26.1.2

Affected products

3

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.