Emqx

Nanomq

32 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.5%
  • Veröffentlicht 20.04.2026 19:23:09
  • Zuletzt bearbeitet 22.04.2026 17:32:15

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.11 have a remotely triggerable heap buffer overflow in the `uri_param_parse` function of NanoMQ's REST API. The vulnerability occurs due to an off-by-one err...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 02.04.2026 17:52:51
  • Zuletzt bearbeitet 10.04.2026 15:59:59

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.10, in NanoMQ's webhook_inproc.c, the hook_work_cb() function processes nng messages by parsing the message body with cJSON_Parse(body). The body is obtained ...

Exploit
  • EPSS 0.4%
  • Veröffentlicht 30.03.2026 20:11:30
  • Zuletzt bearbeitet 13.04.2026 14:07:31

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In NanoMQ version 0.24.6, after enabling auth.http_auth (HTTP authentication), when a client connects to the broker using MQTT CONNECT without providing username/password, and the ...

Exploit
  • EPSS 0.47%
  • Veröffentlicht 30.03.2026 20:11:08
  • Zuletzt bearbeitet 02.04.2026 15:33:55

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.8, NanoMQ’s MQTT-over-WebSocket transport can be crashed by sending an MQTT packet with a deliberately large Remaining Length in the fixed header while provid...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 11.03.2026 15:22:32
  • Zuletzt bearbeitet 17.03.2026 19:20:17

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. MQTT v5 Variable Byte Integer parsing out-of-bounds: get_var_integer() accepts 5-byte varints without bounds checks; reliably triggers OOB read / crash when built with ASan. This a...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 04.03.2026 21:55:11
  • Zuletzt bearbeitet 18.03.2026 16:09:07

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In version 0.24.6, by generating a combined traffic pattern of high-frequency publishes and rapid reconnect/kick-out using the same ClientID and massive subscribe/unsubscribe jitte...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 04.02.2026 19:25:12
  • Zuletzt bearbeitet 20.02.2026 21:20:09

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In version 0.24.6, NanoMQ has a protocol parsing / forwarding inconsistency when handling shared subscriptions ($share/). A malformed SUBSCRIBE topic such as $share/ab (missing the...

  • EPSS 0.32%
  • Veröffentlicht 15.01.2026 00:00:00
  • Zuletzt bearbeitet 03.04.2026 16:16:22

NanoMQ v0.22.7 is vulnerable to Denial of Service (DoS) due to improper resource throttling. A crafted sequence of requests causes the recv-q queue to saturate, leading to the rapid exhaustion of system file descriptors (FDs). This exhaustion trigger...

  • EPSS 0.31%
  • Veröffentlicht 01.01.2026 15:15:41
  • Zuletzt bearbeitet 18.02.2026 16:34:58

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.5 have a Heap-Use-After-Free (UAF) vulnerability within the MQTT bridge client component (implemented via the underlying NanoNNG library). The vulnerability ...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 27.12.2025 01:15:41
  • Zuletzt bearbeitet 30.01.2026 21:14:23

NanoMQ MQTT Broker (NanoMQ) is an Edge Messaging Platform. Prior to version 0.24.2, there is a classical data racing issue about sub info list which could result in heap use after free crash. This issue has been patched in version 0.24.2.