MQTT does not validate hostnames
High severity GitHub Reviewed Published Nov 6, 2025 to the GitHub Advisory Database • Updated Nov 6, 2025
Description
Published by the National Vulnerability DatabaseNov 6, 2025
Published to the GitHub Advisory Database Nov 6, 2025
Last updated Nov 6, 2025
Reviewed Nov 6, 2025
A flaw was found in Rubygem MQTT. By default, the package used to not have hostname validation, resulting in possible Man-in-the-Middle (MITM) attack.
References