CVE-2026-5857
Last modified
CVE-2026-5857 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking topic_len against the 64-byte limit, so an over-length topic returns early but leaves the flag set. On the next TCP segment, tcp_input() re-invokes the parser with topic_received==0, and the persisted topic_len_received==1 skips the length-reading block containing the guard, falling through directly to a memcpy() that uses the unvalidated 16-bit topic_len as the copy length. EPSS estimates a 0.92% chance of exploitation in the next 30 days.
Description
Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking topic_len against the 64-byte limit, so an over-length topic returns early but leaves the flag set. On the next TCP segment, tcp_input() re-invokes the parser with topic_received==0, and the persisted topic_len_received==1 skips the length-reading block containing the guard, falling through directly to a memcpy() that uses the unvalidated 16-bit topic_len as the copy length. The 65-byte topic[] destination overruns into adjacent struct fields including the payload_chunk pointer, which subsequent MQTT code dereferences, giving a compromised or attacker-controlled broker an arbitrary-pointer-write primitive. Contiki-NG's MQTT implementation has no TLS support so the connection is plaintext. Impact ranges from information disclosure and denial of service to remote code execution on embedded targets without memory protection.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Contiki-NG | Contiki-NG | < a34a2dbdc8bea784bd2ae5079aa4be520cd74f2d |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-5857?
How severe is CVE-2026-5857?
How do I fix CVE-2026-5857?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-58562Dell Command Update (DCU), versions prior to 5.7.1, contain …7.3
- CVE-2026-58564Dell Command Update (DCU), versions prior to 5.7.1, contain …7.8
- CVE-2026-58565Dell Command Update (DCU), versions prior to 5.7.1, contain …8.8
- CVE-2026-58566Dell PowerStore, an Incorrect Authorization vulnerability. A…8.8
- CVE-2026-58567Dell PowerStore contains an OS Command Injection vulnerabili…8.8
- CVE-2026-58569Dell PowerStore contains an Inclusion of Functionality from …8.8
- CVE-2026-58571Dell PowerStore contains an OS Command Injection vulnerabili…8.8
- CVE-2026-58572Dell PowerStore contains a Code Injection vulnerability. An …8.8
- CVE-2026-58574Dell PowerStore contains a Missing Authentication for Critic…9.8
- CVE-2026-58575Dell PowerStore contains an Authentication Bypass by Spoofin…8.8
- CVE-2026-58578LobeChat before version 2.2.10-canary.15 contains a regular …7.1
- CVE-2026-58579RAGFlow before 0.26.3 stores an agent pipeline (DSL) node na…5.4
Are you affected by CVE-2026-5857?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
