{"id":"CVE-2020-13410","aliases":["GHSA-gh78-48h3-frjq"],"url":"https://o3.security/vulnerability/CVE-2020-13410","summary":"Improper exception handling in Aedes","details":"An issue was discovered in MoscaJS Aedes 0.42.0. lib/write.js does not properly consider exceptions during the writing of an invalid packet to a stream.","published":"2020-08-26T15:15:12.727Z","modified":"2026-07-09T00:21:11.884275Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"aedes","fixedVersion":"0.42.1"}],"fix":{"url":"https://github.com/moscajs/aedes/pull/493","label":"moscajs/aedes#493"},"references":[{"type":"FIX","url":"https://github.com/moscajs/aedes/pull/493"},{"type":"ARTICLE","url":"https://cwe.mitre.org/data/definitions/248.html"},{"type":"EVIDENCE","url":"https://payatu.com/advisory/dos-in-aedes-mqtt-broker"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T00:21:11.884275Z"}}