All the vulnerabilities related to the version 4.0.3 of the package
Denial of Service in mqtt-packet
Versions of mqtt-packet
prior to 3.4.6, or 4.x prior to 4.0.5 are affected by a denial of service vulnerability wherein specific sequences of MQTT packets can crash the application.
Version 3.x: Update to version 3.4.6 or later. Version 4.x: Update to version 4.0.5 or later.
Improper Input Validation and Buffer Over-read in mqtt-packet
A specifically malformed MQTT Subscribe packet crashes MQTT Brokers using the mqtt-packet module versions < 3.5.1, 4.0.0 - 4.1.3, 5.0.0 - 5.6.1, 6.0.0 - 6.1.2 for decoding.