Contiki-NG disclosed and patched CVE-2026-5857, a high-severity memory corruption flaw in its MQTT client that can be triggered by a malicious or compromised broker. The bug resides in parse_publish_vhdr() and stems from parser state being preserved across TCP segments: topic_len_received can be set before the incoming topic length is validated against the 64-byte limit, allowing a later segment to bypass the check and reach a memcpy() with an unvalidated 16-bit length. That can overflow the 65-byte topic buffer, corrupt adjacent fields such as payload_chunk, and potentially create an arbitrary-pointer-write condition that could lead to information disclosure, denial of service, or possible remote code execution on embedded devices lacking memory protection.
The fix was merged through pull request #3163 in commit a34a2dbdc8bea784bd2ae5079aa4be520cd74f2d, which broadly hardens Contiki-NG's MQTT TCP input parsing. In addition to blocking oversized PUBLISH topic lengths, the update adds stricter validation for MQTT v5 property lengths, safer payload-copying logic, improved handling of partial fields split across TCP segments, and protections for multiple MQTT packets coalesced into a single segment. The patched code now aborts connections on malformed input and addresses related parser issues including integer underflow, out-of-bounds reads, malformed length handling, incorrect Variable Byte Integer decoding, and state corruption across packet boundaries.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
On August 6, 2026, CVE-2026-5857 was published for an out-of-bounds write in Contiki-NG's MQTT client parse_publish_vhdr() logic. The CVE states versions earlier than commit a34a2db are affected and references the fixing commit and pull request #3163.
On July 10, 2026, Contiki-NG merged commit a34a2db into the develop/v5.2 branch via pull request #3163. The patch hardened MQTT TCP input parsing against malformed and coalesced packets, added stricter bounds checks, and aborts connections on malformed input.
On June 22, 2026, Contiki-NG added pull request #3163 with security-relevant fixes for MQTT input parsing, including checks for malformed PUBLISH topic lengths, MQTT v5 property-length handling, Variable Byte Integer decoding, and TCP-segment boundary parsing issues.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.