Home

Description

A flaw was found in Rubygem MQTT. By default, the package used to not have hostname validation, resulting in possible Man-in-the-Middle (MITM) attack.

PUBLISHED Reserved 2025-11-06 | Published 2025-11-06 | Updated 2025-11-08 | Assigner redhat




HIGH: 7.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Problem types

Path Traversal: '..filename'

Product status

Default status
affected

Default status
affected

Timeline

2025-11-06:Reported to Red Hat.
2025-11-06:Made public.

References

access.redhat.com/security/cve/CVE-2025-12790 vdb-entry

bugzilla.redhat.com/show_bug.cgi?id=2413004 (RHBZ#2413004) issue-tracking

github.com/njh/ruby-mqtt/blob/main/NEWS.md

cve.org (CVE-2025-12790)

nvd.nist.gov (CVE-2025-12790)

Download JSON