eclipse-paho / eclipse-paho/paho.mqtt.java
CVE-2025-10543
- Dominant language
- Java
- Stars
- 2.3k
- Forks
- 919
- PR merge metrics
- No merged PRs in 30d
Description
Hello
with
./gradlew dependencyCheckAnalyze
i found
`org.eclipse.paho.client.mqttv3-1.2.5.jar (pkg:maven/org.eclipse.paho/org.eclipse.paho.client.mqttv3@1.2.5, cpe:2.3:a:eclipse:paho_java_client:1.2.5:*:*:*:*:*:*:*, cpe:2.3:a:eclipse:paho_mqtt:1.2.5:*:*:*:*:*:*:*) : CVE-2025-10543`
I think it's a false positive, since the CVE doesn't mention Java. What do you think?
Regards
cyberrranger
Contributor guide
Research direction
Start by running ./gradlew dependencyCheckAnalyze and reviewing the reported org.eclipse.paho.client.mqttv3 1.2.5 dependency alongside CVE-2025-10543. Done means determining whether the finding applies to this Java client and recording a clear conclusion; the issue does not mention a source file or test.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- security
- Issue type
- Bug
- Difficulty
- 1/5
- Estimated time
- Under an hour
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100