Emqx

Nanomq

31 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.06%
  • Veröffentlicht 02.04.2026 17:52:51
  • Zuletzt bearbeitet 10.04.2026 15:59:59

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.10, in NanoMQ's webhook_inproc.c, the hook_work_cb() function processes nng messages by parsing the message body with cJSON_Parse(body). The body is obtained ...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 30.03.2026 20:11:30
  • Zuletzt bearbeitet 13.04.2026 14:07:31

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In NanoMQ version 0.24.6, after enabling auth.http_auth (HTTP authentication), when a client connects to the broker using MQTT CONNECT without providing username/password, and the ...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 30.03.2026 20:11:08
  • Zuletzt bearbeitet 02.04.2026 15:33:55

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.8, NanoMQ’s MQTT-over-WebSocket transport can be crashed by sending an MQTT packet with a deliberately large Remaining Length in the fixed header while provid...

Exploit
  • EPSS 0.07%
  • Veröffentlicht 11.03.2026 15:22:32
  • Zuletzt bearbeitet 17.03.2026 19:20:17

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. MQTT v5 Variable Byte Integer parsing out-of-bounds: get_var_integer() accepts 5-byte varints without bounds checks; reliably triggers OOB read / crash when built with ASan. This a...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 04.03.2026 21:55:11
  • Zuletzt bearbeitet 18.03.2026 16:09:07

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In version 0.24.6, by generating a combined traffic pattern of high-frequency publishes and rapid reconnect/kick-out using the same ClientID and massive subscribe/unsubscribe jitte...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 04.02.2026 19:25:12
  • Zuletzt bearbeitet 20.02.2026 21:20:09

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In version 0.24.6, NanoMQ has a protocol parsing / forwarding inconsistency when handling shared subscriptions ($share/). A malformed SUBSCRIBE topic such as $share/ab (missing the...

  • EPSS 0.02%
  • Veröffentlicht 15.01.2026 00:00:00
  • Zuletzt bearbeitet 03.04.2026 16:16:22

NanoMQ v0.22.7 is vulnerable to Denial of Service (DoS) due to improper resource throttling. A crafted sequence of requests causes the recv-q queue to saturate, leading to the rapid exhaustion of system file descriptors (FDs). This exhaustion trigger...

  • EPSS 0.05%
  • Veröffentlicht 01.01.2026 15:15:41
  • Zuletzt bearbeitet 18.02.2026 16:34:58

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.5 have a Heap-Use-After-Free (UAF) vulnerability within the MQTT bridge client component (implemented via the underlying NanoNNG library). The vulnerability ...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 27.12.2025 01:15:41
  • Zuletzt bearbeitet 30.01.2026 21:14:23

NanoMQ MQTT Broker (NanoMQ) is an Edge Messaging Platform. Prior to version 0.24.2, there is a classical data racing issue about sub info list which could result in heap use after free crash. This issue has been patched in version 0.24.2.

  • EPSS 0.05%
  • Veröffentlicht 15.12.2025 20:19:17
  • Zuletzt bearbeitet 30.01.2026 21:14:03

NanoMQ is a messaging broker/bus for IoT Edge & SDV. Versions prior to 0.24.4 have a buffer overflow case while the PUBLISH packets trigger both shared subscription and vanila subscription. This is fixed in version 0.24.4. As a workaround, disable sh...