CVE-2026-34608
- EPSS 0.06%
- Veröffentlicht 02.04.2026 17:52:51
- Zuletzt bearbeitet 10.04.2026 15:59:59
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.10, in NanoMQ's webhook_inproc.c, the hook_work_cb() function processes nng messages by parsing the message body with cJSON_Parse(body). The body is obtained ...
CVE-2026-32696
- EPSS 0.03%
- Veröffentlicht 30.03.2026 20:11:30
- Zuletzt bearbeitet 13.04.2026 14:07:31
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In NanoMQ version 0.24.6, after enabling auth.http_auth (HTTP authentication), when a client connects to the broker using MQTT CONNECT without providing username/password, and the ...
CVE-2026-25627
- EPSS 0.02%
- Veröffentlicht 30.03.2026 20:11:08
- Zuletzt bearbeitet 02.04.2026 15:33:55
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.8, NanoMQ’s MQTT-over-WebSocket transport can be crashed by sending an MQTT packet with a deliberately large Remaining Length in the fixed header while provid...
CVE-2026-21888
- EPSS 0.07%
- Veröffentlicht 11.03.2026 15:22:32
- Zuletzt bearbeitet 17.03.2026 19:20:17
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. MQTT v5 Variable Byte Integer parsing out-of-bounds: get_var_integer() accepts 5-byte varints without bounds checks; reliably triggers OOB read / crash when built with ASan. This a...
CVE-2026-22040
- EPSS 0.04%
- Veröffentlicht 04.03.2026 21:55:11
- Zuletzt bearbeitet 18.03.2026 16:09:07
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In version 0.24.6, by generating a combined traffic pattern of high-frequency publishes and rapid reconnect/kick-out using the same ClientID and massive subscribe/unsubscribe jitte...
CVE-2025-68699
- EPSS 0.08%
- Veröffentlicht 04.02.2026 19:25:12
- Zuletzt bearbeitet 20.02.2026 21:20:09
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In version 0.24.6, NanoMQ has a protocol parsing / forwarding inconsistency when handling shared subscriptions ($share/). A malformed SUBSCRIBE topic such as $share/ab (missing the...
CVE-2024-48077
- EPSS 0.02%
- Veröffentlicht 15.01.2026 00:00:00
- Zuletzt bearbeitet 03.04.2026 16:16:22
NanoMQ v0.22.7 is vulnerable to Denial of Service (DoS) due to improper resource throttling. A crafted sequence of requests causes the recv-q queue to saturate, leading to the rapid exhaustion of system file descriptors (FDs). This exhaustion trigger...
CVE-2025-66023
- EPSS 0.05%
- Veröffentlicht 01.01.2026 15:15:41
- Zuletzt bearbeitet 18.02.2026 16:34:58
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.5 have a Heap-Use-After-Free (UAF) vulnerability within the MQTT bridge client component (implemented via the underlying NanoNNG library). The vulnerability ...
CVE-2025-59946
- EPSS 0.06%
- Veröffentlicht 27.12.2025 01:15:41
- Zuletzt bearbeitet 30.01.2026 21:14:23
NanoMQ MQTT Broker (NanoMQ) is an Edge Messaging Platform. Prior to version 0.24.2, there is a classical data racing issue about sub info list which could result in heap use after free crash. This issue has been patched in version 0.24.2.
- EPSS 0.05%
- Veröffentlicht 15.12.2025 20:19:17
- Zuletzt bearbeitet 30.01.2026 21:14:03
NanoMQ is a messaging broker/bus for IoT Edge & SDV. Versions prior to 0.24.4 have a buffer overflow case while the PUBLISH packets trigger both shared subscription and vanila subscription. This is fixed in version 0.24.4. As a workaround, disable sh...