Skip to main content

Vendor archive

emqx CVEs

Beta · best-effort

40 CVEs tagged to vendor emqx0 Critical, 22 High, 15 Medium, 3 Low, 0 Unrated.

CVE-2026-36590

Published Jul 15, 2026

An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qos_db_set function in broker_tcp.c component

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-8741

Published May 17, 2026

A vulnerability has been found in EMQX up to 6.2.0. This affects an unknown function of the file apps/emqx/src/emqx_persistent_session_ds.erl of the component QoS 2 PUBLISH Packet…

CVSS 1.3 · Low
evidence mentions
5
Buzz score
28.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-32135

Published Apr 20, 2026

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.11 have a remotely triggerable heap buffer overflow in the `uri_param_parse` function…

CVSS 7.7 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-34608

Published Apr 2, 2026

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.10, in NanoMQ's webhook_inproc.c, the hook_work_cb() function processes nng messages by…

CVSS 4.9 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-30867

Published Apr 2, 2026

CocoaMQTT is a MQTT 5.0 client library for iOS and macOS written in Swift. Prior to version 2.2.2, a vulnerability exists in the packet parsing logic of CocoaMQTT that allows an a…

CVSS 5.7 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-32696

Published Mar 30, 2026

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In NanoMQ version 0.24.6, after enabling auth.http_auth (HTTP authentication), when a client connects to the…

CVSS 3.1 · Low
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-25627

Published Mar 30, 2026

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.8, NanoMQ’s MQTT-over-WebSocket transport can be crashed by sending an MQTT packet with…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-21888

Published Mar 11, 2026

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. MQTT v5 Variable Byte Integer parsing out-of-bounds: get_var_integer() accepts 5-byte varints without bounds…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-22040

Published Mar 4, 2026

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In version 0.24.6, by generating a combined traffic pattern of high-frequency publishes and rapid reconnect/k…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-68699

Published Feb 4, 2026

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In version 0.24.6, NanoMQ has a protocol parsing / forwarding inconsistency when handling shared subscription…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-48077

Published Jan 15, 2026

NanoMQ v0.22.7 is vulnerable to Denial of Service (DoS) due to improper resource throttling. A crafted sequence of requests causes the recv-q queue to saturate, leading to the rap…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66023

Published Jan 1, 2026

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.5 have a Heap-Use-After-Free (UAF) vulnerability within the MQTT bridge client compone…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59946

Published Dec 27, 2025

NanoMQ MQTT Broker (NanoMQ) is an Edge Messaging Platform. Prior to version 0.24.2, there is a classical data racing issue about sub info list which could result in heap use after…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59947

Published Dec 15, 2025

NanoMQ is a messaging broker/bus for IoT Edge & SDV. Versions prior to 0.24.4 have a buffer overflow case while the PUBLISH packets trigger both shared subscription and vanila sub…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42655

Published Jul 29, 2025

An access control issue in NanoMQ v0.21.10 allows attackers to bypass security restrictions and access sensitive system topic messages using MQTT wildcard characters.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42651

Published Jul 29, 2025

NanoMQ v0.17.9 was discovered to contain a heap use-after-free vulnerability via the component sub_Ctx_handle. This vulnerability allows attackers to cause a Denial of Service (Do…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42650

Published Jul 15, 2025

NanoMQ 0.17.5 was discovered to contain a segmentation fault via the component /nanomq/pub_handler.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42649

Published Jul 14, 2025

NanoMQ v0.22.10 was discovered to contain a memory leak which allows attackers to cause a Denial of Service (DoS) via a crafted PUBLISH message.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42648

Published Jul 14, 2025

NanoMQ v0.22.10 was discovered to contain a heap overflow which allows attackers to cause a Denial of Service (DoS) via a crafted CONNECT message.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42646

Published Jul 14, 2025

A segmentation fault in NanoMQ v0.21.10 allows attackers to cause a Denial of Service (DoS) via crafted messages.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-10965

Published Nov 7, 2024

A vulnerability classified as problematic was found in emqx neuron up to 2.10.0. Affected by this vulnerability is an unknown functionality of the file /api/v2/schema of the compo…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10964

Published Nov 7, 2024

A vulnerability classified as critical has been found in emqx neuron up to 2.10.0. Affected is the function handle_add_plugin in the library cmd.library of the file plugins/restfu…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-44460

Published Sep 12, 2024

An invalid read size in Nanomq v0.21.9 allows attackers to cause a Denial of Service (DoS).

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-31036

Published Apr 22, 2024

A heap-buffer-overflow vulnerability in the read_byte function in NanoMQ v.0.21.7 allows attackers to cause a denial of service via transmission of crafted hexstreams.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31041

Published Apr 17, 2024

Null Pointer Dereference vulnerability in topic_filtern function in mqtt_parser.c in NanoMQ 0.21.7 allows attackers to cause a denial of service.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 40 CVEsPage 1 of 2