coreMQTT v5.0.0 Heap Overflow – Update Required
coreMQTT before version 5.0.1 has a nasty heap out-of-bounds read vulnerability (CVE-2026-8686) in MQTT v5.0 property parsing. A malicious broker can crash your device by sending a crafted UNSUBACK or SUBACK packet. If you're running v5.0.0, patch to 5.0.1 immediately—this one's marked Important by AWS.
source: [aws/security-bulletin]