{"id":"CVE-2025-63235","title":"In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CONNECT packets","summary":"In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CONNECT packets. When clients send invalid CONNECT packets - either due to repeated attempts or failed authentication - …","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-400"],"published":"2026-08-07","updated":"2026-09-29","sourceUpdated":"2026-09-29T11:10:00.150","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-63235","references":[{"url":"https://github.com/codepr/sol/issues/12","label":"cve@mitre.org"},{"url":"https://github.com/peter-pe/sol-vulnerabilities/blob/main/CVE-2025-63235.md","label":"cve@mitre.org"},{"url":"https://github.com/codepr/sol/issues/12","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://github.com/peter-pe/sol-vulnerabilities/blob/main/CVE-2025-63235.md","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd"],"ingestedAt":"2026-09-29T11:32:41.220Z","slug":"CVE-2025-63235","body":"## Overview\n\nIn sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CONNECT packets. When clients send invalid CONNECT packets - either due to repeated attempts or failed authentication - the server may silently drop the connection or send a CONNACK but fail to close the session or deallocate internal resources. This behavior allows an attacker to create numerous half-open connections that consume memory and file descriptors indefinitely, potentially triggering the Linux OOM killer and causing a denial of service.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}