Please report all vulnerabilities to https://github.com/moscajs/aedes/security.
Security: moscajs/aedes
Security
SECURITY.md
-
Cross-session QoS2 dedup residue silently swallows the first colliding message after clean-session reconnectGHSA-p8r9-qf8w-p73r published
Sep 16, 2026 by robertsLandoModerate -
Remote unauthenticated denial of service: a single SUBSCRIBE, UNSUBSCRIBE or CONNECT using an Object.prototype property name (e.g. "constructor", "__proto__") crashes the aedes broker processGHSA-52qw-whmv-87c5 published
Sep 15, 2026 by robertsLandoHigh -
Aedes retains unbounded inbound QoS 2 packet state before PUBRELGHSA-5jvp-3p2v-5qgf published
Sep 16, 2026 by robertsLandoHigh -
Uncaught Exception and Uncontrolled Resource Consumption in aedesGHSA-xxqp-5qx8-gj5q published
Jun 30, 2026 by robertsLandoHigh
Learn more about advisories related to moscajs/aedes in the GitHub Advisory Database