---
id: CVE-2026-5857
title: >-
  Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c
  sets topic_len_received=1 before checking topic_len against the 64-byte limit,
  so an over-length topic returns early but leaves the flag set
summary: >-
  Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c
  sets topic_len_received=1 before checking topic_len against the 64-byte limit,
  so an over-length topic returns early but leaves the flag set. On the next TCP
  s…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-787
published: '2026-08-06'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T20:06:30.133'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-5857'
references:
  - url: 'https://github.com/contiki-ng/contiki-ng'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/contiki-ng/contiki-ng/commit/a34a2dbdc8bea784bd2ae5079aa4be520cd74f2d
    label: disclosure@vulncheck.com
  - url: 'https://github.com/contiki-ng/contiki-ng/pull/3163'
    label: disclosure@vulncheck.com
  - url: 'https://y637f9qq2x.com/posts/cve-2026-5857/'
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00919
epssPercentile: 0.58548
ingestedAt: '2026-08-09T00:31:25.015Z'
---

## Overview

Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking topic_len against the 64-byte limit, so an over-length topic returns early but leaves the flag set. On the next TCP segment, tcp_input() re-invokes the parser with topic_received==0, and the persisted topic_len_received==1 skips the length-reading block containing the guard, falling through directly to a memcpy() that uses the unvalidated 16-bit topic_len as the copy length. The 65-byte topic[] destination overruns into adjacent struct fields including the payload_chunk pointer, which subsequent MQTT code dereferences, giving a compromised or attacker-controlled broker an arbitrary-pointer-write primitive. Contiki-NG's MQTT implementation has no TLS support so the connection is plaintext. Impact ranges from information disclosure and denial of service to remote code execution on embedded targets without memory protection.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
