Skip to main content

Vendor/product archive

emqx / nanomq CVEs

Beta · best-effort

33 CVEs tagged to emqx / nanomq0 Critical, 21 High, 10 Medium, 2 Low, 0 Unrated.

CVE-2026-36590

Published Jul 15, 2026

An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qos_db_set function in broker_tcp.c component

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-32135

Published Apr 20, 2026

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.11 have a remotely triggerable heap buffer overflow in the `uri_param_parse` function…

CVSS 7.7 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-34608

Published Apr 2, 2026

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.10, in NanoMQ's webhook_inproc.c, the hook_work_cb() function processes nng messages by…

CVSS 4.9 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-32696

Published Mar 30, 2026

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In NanoMQ version 0.24.6, after enabling auth.http_auth (HTTP authentication), when a client connects to the…

CVSS 3.1 · Low
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-25627

Published Mar 30, 2026

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.8, NanoMQ’s MQTT-over-WebSocket transport can be crashed by sending an MQTT packet with…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-21888

Published Mar 11, 2026

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. MQTT v5 Variable Byte Integer parsing out-of-bounds: get_var_integer() accepts 5-byte varints without bounds…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-22040

Published Mar 4, 2026

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In version 0.24.6, by generating a combined traffic pattern of high-frequency publishes and rapid reconnect/k…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-68699

Published Feb 4, 2026

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In version 0.24.6, NanoMQ has a protocol parsing / forwarding inconsistency when handling shared subscription…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-48077

Published Jan 15, 2026

NanoMQ v0.22.7 is vulnerable to Denial of Service (DoS) due to improper resource throttling. A crafted sequence of requests causes the recv-q queue to saturate, leading to the rap…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66023

Published Jan 1, 2026

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.5 have a Heap-Use-After-Free (UAF) vulnerability within the MQTT bridge client compone…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59946

Published Dec 27, 2025

NanoMQ MQTT Broker (NanoMQ) is an Edge Messaging Platform. Prior to version 0.24.2, there is a classical data racing issue about sub info list which could result in heap use after…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59947

Published Dec 15, 2025

NanoMQ is a messaging broker/bus for IoT Edge & SDV. Versions prior to 0.24.4 have a buffer overflow case while the PUBLISH packets trigger both shared subscription and vanila sub…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42655

Published Jul 29, 2025

An access control issue in NanoMQ v0.21.10 allows attackers to bypass security restrictions and access sensitive system topic messages using MQTT wildcard characters.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42651

Published Jul 29, 2025

NanoMQ v0.17.9 was discovered to contain a heap use-after-free vulnerability via the component sub_Ctx_handle. This vulnerability allows attackers to cause a Denial of Service (Do…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42650

Published Jul 15, 2025

NanoMQ 0.17.5 was discovered to contain a segmentation fault via the component /nanomq/pub_handler.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42649

Published Jul 14, 2025

NanoMQ v0.22.10 was discovered to contain a memory leak which allows attackers to cause a Denial of Service (DoS) via a crafted PUBLISH message.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42648

Published Jul 14, 2025

NanoMQ v0.22.10 was discovered to contain a heap overflow which allows attackers to cause a Denial of Service (DoS) via a crafted CONNECT message.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42646

Published Jul 14, 2025

A segmentation fault in NanoMQ v0.21.10 allows attackers to cause a Denial of Service (DoS) via crafted messages.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-44460

Published Sep 12, 2024

An invalid read size in Nanomq v0.21.9 allows attackers to cause a Denial of Service (DoS).

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-31036

Published Apr 22, 2024

A heap-buffer-overflow vulnerability in the read_byte function in NanoMQ v.0.21.7 allows attackers to cause a denial of service via transmission of crafted hexstreams.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31041

Published Apr 17, 2024

Null Pointer Dereference vulnerability in topic_filtern function in mqtt_parser.c in NanoMQ 0.21.7 allows attackers to cause a denial of service.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-31040

Published Apr 17, 2024

Buffer Overflow vulnerability in the get_var_integer function in mqtt_parser.c in NanoMQ 0.21.7 allows remote attackers to cause a denial of service via a series of specially craf…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-25767

Published Feb 26, 2024

nanomq 0.21.2 contains a Use-After-Free vulnerability in /nanomq/nng/src/core/socket.c.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-34494

Published Jun 12, 2023

NanoMQ 0.16.5 is vulnerable to heap-use-after-free in the nano_ctx_send function of nmq_mqtt.c.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34488

Published Jun 12, 2023

NanoMQ 0.17.5 has a one-byte heap-based buffer over-read in the conn_handler function of mqtt_parser.c when it processes malformed messages.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 33 CVEsPage 1 of 2