IoT & Hardware
Denial of Service
DoS in aedes MQTT broker
DoS on aedes broker because of incorrect error handling A specifically crafted payload which has published header and message length as 0 is sent to the server which crashes the server because of the…
.png)
Overview
DoS on aedes broker because of incorrect error handling
A specifically crafted payload which has published header and message length as 0 is sent to the server which crashes the server because of the improper error handling in writeNumberCached while trying to create a packet for Publish Release which fails at stream.write() as the datatype is an undefined array with -1 number as it is the packet id of the packet.
Vulnerability details
DoS on aedes broker because of incorrect error handling A specifically crafted payload which has published header and message length as 0 is sent to the server which crashes the server because of the improper error handling in writeNumberCached while trying
Disclosure timeline
2020-05-18 reported to the vendor
2020-05-22 Issue was fixed.
References
2026-06-17 (NVD record)
Credits
Arun Magesh
















