{"id":"CVE-2019-11777","details":"In the Eclipse Paho Java client library version 1.2.0, when connecting to an MQTT server using TLS and setting a host name verifier, the result of that verification is not checked. This could allow one MQTT server to impersonate another and provide the client library with incorrect information.","aliases":["GHSA-63qc-p2x4-9fgf"],"modified":"2026-08-27T08:13:57.785293Z","published":"2019-09-11T18:15:10.757Z","references":[{"type":"REPORT","url":"https://bugs.eclipse.org/bugs/show_bug.cgi?id=549934"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/eclipse-paho/paho.mqtt.java","events":[{"introduced":"e36f2ec59c260e97a9fb832d4e83faadd588ff4a"},{"last_affected":"e36f2ec59c260e97a9fb832d4e83faadd588ff4a"}],"database_specific":{"cpe":"cpe:2.3:a:eclipse:paho_java_client:1.2.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.2.0"},{"last_affected":"1.2.0"}],"source":"CPE_STRING"}}],"versions":["1.2.0","v1.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-11777.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}