Medium severity5.5NVD Advisory· Published Nov 24, 2025· Updated Jun 17, 2026
CVE-2025-65503
CVE-2025-65503
Description
Use after free in endpoint destructors in Redboltz async_mqtt 10.2.5 allows local users to cause a denial of service via triggering SSL initialization failure that results in incorrect destruction order between io_context and endpoint objects.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:redboltz:async_mqtt:10.2.5:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:redboltz:async_mqtt:10.2.5:*:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: <10.2.5
Patches
Vulnerability mechanics
References
2- github.com/redboltz/async_mqtt/pull/437nvdIssue TrackingPatch
- github.com/redboltz/async_mqtt/issues/436nvdExploitIssue TrackingPatch
News mentions
0No linked articles in our index yet.