VDB
GO-2025-4173
GO-2025-4173
PUBLISHED
Eclipse Paho Go MQTT may incorrectly encode strings if length exceeds 65535 bytes in github.com/eclipse/paho.mqtt.golang
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| chainguard | beats-fips-8.19 | 0, 0, 0 |
| chainguard | agentbeat-fips | 0, 0, 0 |
| chainguard | falcosidekick-fips | 0, 0, 0 |
| chainguard | agentbeat | 0, 0, 0 |
| chainguard | elastic-agent-fips-8.19 | 0, 0, 0 |
| chainguard | beats-fips-8.17 | 0, 0, 0 |
| chainguard | dapr-fips-1.15 | 0, 0, 0 |
| chainguard | beats-fips-9.1 | 0, 0, 0 |
| wolfi | minio | 0, 0, 0 |
| chainguard | beats-9.1 | 0, 0, 0 |
| chainguard | beats-8.18 | 0, 0, 0 |
| chainguard | elastic-agent-fips-8.18 | 0, 0, 0 |
| chainguard | influxd-2.7 | 0, 0, 0 |
| chainguard | elastic-agent-9.1 | 0, 0, 0 |
| wolfi | falcosidekick | 0, 0, 0 |
| chainguard | zabbix-agent2-fips-6.0 | 0, 0, 0 |
| chainguard | elastic-agent | 0, 0, 0 |
| chainguard | elastic-agent-8.18 | 0, 0, 0 |
| chainguard | telegraf-1.35 | 0, 0, 0 |
| chainguard | beats-7 | 0, 0, 0 |
…and 21 more
Timeline
- Dec 15, 2025 CVE Published
- Feb 4, 2026 CVE Updated
References
- https://github.com/advisories/GHSA-32fw-gq77-f2f2 advisory
- https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/254 url
- https://github.com/eclipse-paho/paho.mqtt.golang/issues/730 discussion
- https://github.com/alpinelinux/build-server-status/commit/e3487897db32c8c3d0287643f8384a6669e93731 fix
- https://github.com/eclipse-paho/paho.mqtt.golang/pull/714 fix