Skip to content

Instantly share code, notes, and snippets.

@jforge
Last active February 21, 2022 10:06
Show Gist options
  • Select an option

  • Save jforge/32b70ac03938ad9b36da3b1ea7a3da21 to your computer and use it in GitHub Desktop.

Select an option

Save jforge/32b70ac03938ad9b36da3b1ea7a3da21 to your computer and use it in GitHub Desktop.

Reason for the VerneMQ extra parameter to limit topic depth:

https://nvd.nist.gov/vuln/detail/CVE-2021-33176

This was mentioned in the VerneMQ Slack channel #announcements: https://vernemq.slack.com/archives/C37K2EKAP/p1623770790005900

afa1 - 2021-06-15 17:26: "" Announcement on https://nvd.nist.gov/vuln/detail/CVE-2021-33176: an authenticated MQTT client can attempt to subscribe to very long topics (with hundreds of topic levels). This may exhaust RAM in the VM. ACLs usually restrict this. In addition, master and release 1.12 plus following have a global config topic_max_depth where you can globally limit topic length, in addition to ACLs. ""

The related change can be found here, the original branch is meanwhile deleted: vernemq/vernemq#1793

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment