{"id":"CVE-2026-102762","published":"2026-09-29T18:17:13.590","lastModified":"2026-09-29T19:00:16.623","description":"The NetX Duo MQTT client leaks the packet carrying a malformed PUBLISH message. Each malformed PUBLISH costs one packet, or one chain of packets, from the network driver's receive pool, and nothing returns it. A peer that can deliver a few dozen such messages exhausts the pool and stops all inbound network traffic on the device until it is rebooted.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-401"],"vendors":[],"products":[],"references":[{"url":"https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-9v23-qwp9-2q3h","tags":[]}],"exploitRefs":[{"url":"https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-9v23-qwp9-2q3h","tags":[]}],"hasPoc":true,"ai":null}