{"id":"CVE-2023-5632","summary":"Unconditionally adding an event to the epoll causes excessive CPU consumption","details":"In Eclipse Mosquito before and including 2.0.5, establishing a connection to the mosquitto server without sending data causes the EPOLLOUT event to be added, which results excessive CPU consumption. This could be used by a malicious actor to perform denial of service type attack. This issue is fixed in 2.0.6\n\n\n","modified":"2026-05-16T11:54:06.216754628Z","published":"2023-10-18T08:34:34.788Z","database_specific":{"cwe_ids":["CWE-834"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/5xxx/CVE-2023-5632.json","cna_assigner":"eclipse"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/5xxx/CVE-2023-5632.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-5632"},{"type":"FIX","url":"https://github.com/eclipse/mosquitto/commit/18bad1ff32435e523d7507e9b2ce0010124a8f2d"},{"type":"FIX","url":"https://github.com/eclipse/mosquitto/pull/2053"},{"type":"PACKAGE","url":"https://github.com/eclipse/mosquitto"}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}