CVE-2021-33175
HIGHEMQ X Broker <4.2.8 - DoS
Title source: llmDescription
EMQ X Broker versions prior to 4.2.8 are vulnerable to a denial of service attack as a result of excessive memory consumption due to the handling of untrusted inputs. These inputs cause the message broker to consume large amounts of memory, resulting in the application being terminated by the operating system.
Scores
CVSS v3
7.5
EPSS
0.0041
EPSS Percentile
61.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-502
CWE-770
Status
published
Affected Products (1)
emqx/emq_x_broker
< 4.2.8
Timeline
Published
Jun 08, 2021
Tracked Since
Feb 18, 2026