Related Vulnerabilities: CVE-2018-12543  

If a message is sent to Mosquitto before 1.5.3 with a topic that begins with $, but is not $SYS, then an assert that should be unreachable is triggered and Mosquitto will exit.

Severity Medium

Remote Yes

Type Denial of service

Description

If a message is sent to Mosquitto before 1.5.3 with a topic that begins with $, but is not $SYS, then an assert that should be unreachable is triggered and Mosquitto will exit.

AVG-772 mosquitto 1.5.1-1 1.5.3-1 Medium Fixed

01 Oct 2018 ASA-201810-1 AVG-772 mosquitto Medium denial of service

https://mosquitto.org/blog/2018/09/security-advisory-cve-2018-12543/
https://github.com/eclipse/mosquitto/commit/f7474d348225bf086f6b9c69b18d6413aa6ffca6