RubySec

Providing security resources for the Ruby community

CVE-2025-12790 (mqtt): MQTT does not validate hostnames

MQTT does not validate hostnames

Published: November 06, 2025

SECURITY IDENTIFIERS

GEM

mqtt

SEVERITY

CVSS v3.x: 7.4 (High)

PATCHED VERSIONS

>= 0.7.0

DESCRIPTION

A flaw was found in Rubygem MQTT. By default, the package used to not have hostname validation, resulting in possible Man-in-the-Middle (MITM) attack.

RELATED