Browse all 6 CVE security advisories affecting emqx. AI-powered Chinese analysis, POCs, and references for each vulnerability.
EMQX provides an open-source MQTT messaging platform for IoT and real-time communication systems. Historically, vulnerabilities have included remote code execution, cross-site scripting, and privilege escalation, often stemming from input validation flaws and insecure default configurations. The platform has faced security incidents, including a 2021 vulnerability (CVE-2021-3711) allowing unauthorized access due to improper authentication checks. With five CVEs currently recorded, EMQX maintains security through regular updates and emphasizes secure deployment practices, though its complex architecture requires careful configuration to mitigate risks in high-traffic environments.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-44725 | EMQX: Stale plugins allow grants amplify a compromised admin/API key to remote code execution — emqx CWE-345 | 6.6 | Medium | 2026-08-20 |
| CVE-2026-30867 | CocoaMQTT: Denial of Service via Reachable Assertion in `PUBLISH` Packet Parsing — CocoaMQTT CWE-617 | 5.7 | Medium | 2026-04-02 |
| CVE-2025-62413 | MQTTX vulnerable to cross-site scripting via improper message payload rendering — MQTTX CWE-79 | 6.1 | Medium | 2025-10-16 |
| CVE-2025-52136 | EMQX 代码问题漏洞 — EMQX CWE-754 | 3.0 | Low | 2025-08-10 |
| CVE-2024-10965 | emqx neuron JSON File schema information disclosure — neuron CWE-200 | 4.3 | Medium | 2024-11-07 |
| CVE-2024-10964 | emqx neuron plugin_handle.c handle_add_plugin buffer overflow — neuron CWE-120 | 6.3 | Medium | 2024-11-07 |
This page lists every published CVE security advisory associated with emqx. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.