{"id":"CVE-2017-10910","aliases":["GHSA-h9mj-fghc-664w"],"url":"https://o3.security/vulnerability/CVE-2017-10910","summary":"Denial of Service in mqtt","details":"MQTT.js 2.x.x prior to 2.15.0 issue in handling PUBLISH tickets may lead to an attacker causing a denial-of-service condition.","published":"2017-12-28T02:29:03.427Z","modified":"2026-07-08T12:05:28.583361Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"mqtt","fixedVersion":"2.15.0"}],"fix":{"url":"https://github.com/mqttjs/MQTT.js/commit/403ba53b838f2d319a0c0505a045fe00239e9923","label":"mqttjs/MQTT.js@403ba53"},"references":[{"type":"ADVISORY","url":"https://github.com/mqttjs/MQTT.js/releases/tag/v2.15.0"},{"type":"ADVISORY","url":"https://jvn.jp/en/jp/JVN45494523/index.html"},{"type":"FIX","url":"https://github.com/mqttjs/MQTT.js/commit/403ba53b838f2d319a0c0505a045fe00239e9923"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T12:05:28.583361Z"}}