# Any Plan To Address Version 1.3.3 Reported Vulnerabilities?

**URL:** <https://community.hivemq.com/t/any-plan-to-address-version-1-3-3-reported-vulnerabilities/3368>\
**Category:** HiveMQ Client Library\
**Created:** [November 26, 2024, 8:51pm UTC](https://community.hivemq.com/t/any-plan-to-address-version-1-3-3-reported-vulnerabilities/3368 "2024-11-26T20:51:09Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Helium3](https://avatars.discourse-cdn.com/v4/letter/h/a587f6/32.png) [@Helium3](https://community.hivemq.com/u/Helium3)\
**Post date:** [November 26, 2024, 8:51pm UTC](https://community.hivemq.com/t/any-plan-to-address-version-1-3-3-reported-vulnerabilities/3368/1 "2024-11-26T20:51:09Z")

</div>

According to MVN Repository, the most recent version of the client library (1.3.3) was last updated in October 2023. It has three known security vulnerabilities. Is there any plan to address these vulnerabilities and, if so, is there any sense of when that might occur?

---

<div class="post-metadata">

**Author:** ![Daria\_H](https://avatars.discourse-cdn.com/v4/letter/d/dfb087/32.png) [@Daria\_H](https://community.hivemq.com/u/Daria_H)\
**Post date:** [November 29, 2024, 3:06pm UTC](https://community.hivemq.com/t/any-plan-to-address-version-1-3-3-reported-vulnerabilities/3368/2 "2024-11-29T15:06:32Z")

</div>

Hi Aaron,

Thank you for reaching out and bringing up your concerns regarding the security vulnerabilities in [https://mvnrepository.com/artifact/com.hivemq/hivemq-mqtt-client/1.3.3](https://mvnrepository.com/artifact/com.hivemq/hivemq-mqtt-client/1.3.3)

We want to assure you that we are actively working on addressing the identified CVEs, and a future release will include the necessary fixes. Unfortunately, we are unable to provide a specific release date at this time.

In the interim, if you need to mitigate these issues, we recommend building the library from the master branch, which contains the latest updates and fixes. You can find the master branch here:

> **[GitHub - hivemq/hivemq-mqtt-client: HiveMQ MQTT Client is an MQTT 5.0 and MQTT 3.1.1...](https://github.com/hivemq/hivemq-mqtt-client)**
>
> HiveMQ MQTT Client is an MQTT 5.0 and MQTT 3.1.1 compatible and feature-rich high-performance Java client library with different API flavours and backpressure support

We appreciate your understanding and patience as we work to resolve this.

Best regards,  
Dasha from The HiveMQ Team 🐝

---

<div class="post-metadata">

**Author:** ![Antonio](https://avatars.discourse-cdn.com/v4/letter/a/6de8d8/32.png) [@Antonio](https://community.hivemq.com/u/Antonio)\
**Post date:** [December 3, 2024, 3:07pm UTC](https://community.hivemq.com/t/any-plan-to-address-version-1-3-3-reported-vulnerabilities/3368/3 "2024-12-03T15:07:06Z")

</div>

Hello,

New MQTT client has been already released which fixes these CVEs.

[https://github.com/hivemq/hivemq-mqtt-client/releases/tag/v1.3.4](https://github.com/hivemq/hivemq-mqtt-client/releases/tag/v1.3.4)

Also available on [https://central.sonatype.com/artifact/com.hivemq/hivemq-mqtt-client/versions](https://central.sonatype.com/artifact/com.hivemq/hivemq-mqtt-client/versions)

Cheers
