CVE-2025-59946
- EPSS 0.34%
- Veröffentlicht 27.12.2025 01:15:41
- Zuletzt bearbeitet 30.01.2026 21:14:23
NanoMQ MQTT Broker (NanoMQ) is an Edge Messaging Platform. Prior to version 0.24.2, there is a classical data racing issue about sub info list which could result in heap use after free crash. This issue has been patched in version 0.24.2.
- EPSS 0.32%
- Veröffentlicht 15.12.2025 20:19:17
- Zuletzt bearbeitet 30.01.2026 21:14:03
NanoMQ is a messaging broker/bus for IoT Edge & SDV. Versions prior to 0.24.4 have a buffer overflow case while the PUBLISH packets trigger both shared subscription and vanila subscription. This is fixed in version 0.24.4. As a workaround, disable sh...
CVE-2024-42655
- EPSS 0.36%
- Veröffentlicht 29.07.2025 00:00:00
- Zuletzt bearbeitet 06.08.2025 17:46:27
An access control issue in NanoMQ v0.21.10 allows attackers to bypass security restrictions and access sensitive system topic messages using MQTT wildcard characters.
CVE-2024-42651
- EPSS 0.42%
- Veröffentlicht 29.07.2025 00:00:00
- Zuletzt bearbeitet 06.08.2025 16:40:47
NanoMQ v0.17.9 was discovered to contain a heap use-after-free vulnerability via the component sub_Ctx_handle. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SUBSCRIBE message.
CVE-2024-42650
- EPSS 0.55%
- Veröffentlicht 15.07.2025 00:00:00
- Zuletzt bearbeitet 17.07.2025 17:53:31
NanoMQ 0.17.5 was discovered to contain a segmentation fault via the component /nanomq/pub_handler.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PUBLISH message.
CVE-2024-42649
- EPSS 0.31%
- Veröffentlicht 14.07.2025 00:00:00
- Zuletzt bearbeitet 16.07.2025 18:15:23
NanoMQ v0.22.10 was discovered to contain a memory leak which allows attackers to cause a Denial of Service (DoS) via a crafted PUBLISH message.
CVE-2024-42648
- EPSS 0.34%
- Veröffentlicht 14.07.2025 00:00:00
- Zuletzt bearbeitet 16.07.2025 19:15:25
NanoMQ v0.22.10 was discovered to contain a heap overflow which allows attackers to cause a Denial of Service (DoS) via a crafted CONNECT message.
CVE-2024-42646
- EPSS 0.41%
- Veröffentlicht 14.07.2025 00:00:00
- Zuletzt bearbeitet 16.07.2025 19:15:25
A segmentation fault in NanoMQ v0.21.10 allows attackers to cause a Denial of Service (DoS) via crafted messages.
CVE-2024-44460
- EPSS 0.49%
- Veröffentlicht 12.09.2024 20:15:04
- Zuletzt bearbeitet 30.10.2024 19:35:23
An invalid read size in Nanomq v0.21.9 allows attackers to cause a Denial of Service (DoS).
CVE-2024-31036
- EPSS 0.33%
- Veröffentlicht 22.04.2024 22:15:07
- Zuletzt bearbeitet 10.06.2025 01:30:34
A heap-buffer-overflow vulnerability in the read_byte function in NanoMQ v.0.21.7 allows attackers to cause a denial of service via transmission of crafted hexstreams.