eclipse-paho / eclipse-paho/paho.mqtt.java

CVE-2025-10543

Open
#1,101 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
2.3k
Forks
919
PR merge metrics
No merged PRs in 30d

Description

Hello

with

./gradlew dependencyCheckAnalyze

i found

`org.eclipse.paho.client.mqttv3-1.2.5.jar (pkg:maven/org.eclipse.paho/org.eclipse.paho.client.mqttv3@1.2.5, cpe:2.3:a:eclipse:paho_java_client:1.2.5:*:*:*:*:*:*:*, cpe:2.3:a:eclipse:paho_mqtt:1.2.5:*:*:*:*:*:*:*) : CVE-2025-10543`

I think it's a false positive, since the CVE doesn't mention Java. What do you think?

Regards

cyberrranger

Contributor guide

Open the contributing guide

Research direction

Start by running ./gradlew dependencyCheckAnalyze and reviewing the reported org.eclipse.paho.client.mqttv3 1.2.5 dependency alongside CVE-2025-10543. Done means determining whether the finding applies to this Java client and recording a clear conclusion; the issue does not mention a source file or test.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
security
Issue type
Bug
Difficulty
1/5
Estimated time
Under an hour
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.