Vulnerability Report: GO-2025-4173
- CVE-2025-10543, GHSA-32fw-gq77-f2f2
- Affects: github.com/eclipse/paho.mqtt.golang
- Published: Dec 15, 2025
Eclipse Paho Go MQTT may incorrectly encode strings if length exceeds 65535 bytes in github.com/eclipse/paho.mqtt.golang
For detailed information about this vulnerability, visit https://github.com/advisories/GHSA-32fw-gq77-f2f2.
Affected Modules
-
PathGo Versions
-
before v1.5.1
Aliases
References
- https://github.com/advisories/GHSA-32fw-gq77-f2f2
- https://github.com/alpinelinux/build-server-status/commit/e3487897db32c8c3d0287643f8384a6669e93731
- https://github.com/eclipse-paho/paho.mqtt.golang/issues/730
- https://github.com/eclipse-paho/paho.mqtt.golang/pull/714
- https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/254
- https://vuln.go.dev/ID/GO-2025-4173.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.