CVE-2025-10543

MEDIUM
中文标题:
(暂无数据)
英文标题:
In Eclipse Paho Go MQTT v3.1 library (paho.mqtt.golang) versions <=1.5.0 UTF-8 encoded strings, pass...
CVSS分数: 6.3
发布时间: 2025-12-02 08:18:16
漏洞类型: (暂无数据)
状态: PUBLISHED
数据质量分数: 0.40
数据版本: v3
漏洞描述
中文描述:

(暂无数据)

英文描述:

In Eclipse Paho Go MQTT v3.1 library (paho.mqtt.golang) versions <=1.5.0 UTF-8 encoded strings, passed into the library, may be incorrectly encoded if their length exceeds 65535 bytes. This may lead to unexpected content in packets sent to the server (for example, part of an MQTT topic may leak into the message body in a PUBLISH packet). The issue arises because the length of the data passed in was converted from an int64/int32 (depending upon CPU) to an int16 without checks for overflows. The int16 length was then written, followed by the data (e.g. topic). This meant that when the data (e.g. topic) was over 65535 bytes then the amount of data written exceeds what the length field indicates. This could lead to a corrupt packet, or mean that the excess data leaks into another field (e.g. topic leaks into message body).

CWE类型:
CWE-197 CWE-681
标签:
(暂无数据)
受影响产品
厂商 产品 版本 版本范围 平台 CPE
Eclipse Foundation paho.mqtt.golang (Go MQTT v3.1 library) - ≤ 1.5.0 - cpe:2.3:a:eclipse_foundation:paho.mqtt.golang_(go_mqtt_v3.1_library):*:*:*:*:*:*:*:*
eclipse paho_mqtt * - - cpe:2.3:a:eclipse:paho_mqtt:*:*:*:*:*:go:*:*
解决方案
中文解决方案:
(暂无数据)
英文解决方案:
(暂无数据)
临时解决方案:
(暂无数据)
参考链接
无标题 OTHER
cve.org
访问
CVSS评分详情
4.0 (cna)
MEDIUM
6.3
CVSS向量: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
机密性
LOW
完整性
NONE
可用性
NONE
后续系统影响 (Subsequent):
机密性
NONE
完整性
NONE
可用性
NONE
时间信息
发布时间:
2025-12-02 08:18:16
修改时间:
2025-12-02 13:55:51
创建时间:
2026-01-12 02:10:24
更新时间:
2026-01-17 06:00:14
利用信息
暂无可利用代码信息
数据源详情
数据源 记录ID 版本 提取时间
CVE cve_CVE-2025-10543 2025-12-03 03:24:29 2026-01-12 02:10:24
NVD nvd_CVE-2025-10543 2025-12-03 03:25:10 2026-01-12 02:27:21
版本与语言
当前版本: v3
主要语言: EN
支持语言:
EN
安全公告
暂无安全公告信息
变更历史
v3 NVD
2026-01-17 06:00:14
affected_products_count: 1 → 2
查看详细变更
  • affected_products_count: 1 -> 2
v2 NVD
2026-01-12 02:27:21
data_sources: ['cve'] → ['cve', 'nvd']
查看详细变更
  • data_sources: ['cve'] -> ['cve', 'nvd']