VendorsEMQXnanomqall versions
Vulnerabilities

EMQX EMQ Technologies NanoMQ

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

33CVEs
CVE-2025-59947
NanoMQ has Buffer Overflow
Published 2025-12-15 · Analyzed
9.0EPSS 0.003
CVE-2024-42655
An access control issue in NanoMQ v0.21.10 allows attackers to bypass security restrictions and access sensitive system topic messages using MQTT wildcard characters.
Published 2025-07-29 · Analyzed
8.8EPSS 0.004
CVE-2026-34608
nanomq: Heap-Buffer-Overflow in webhook_inproc.c via cJSON_Parse OOB Read
Published 2026-04-02 · Analyzed
8.2EPSS 0.006
CVE-2023-34488
NanoMQ 0.17.5 has a one-byte heap-based buffer over-read in the conn_handler function of mqtt_parser.c when it processes malformed messages.
Published 2023-06-12 · Analyzed
8.0EPSS 0.005
CVE-2026-32135
NanoMQ has Heap Buffer Overflow in URI Parameter Parsing
Published 2026-04-20 · Analyzed
7.7EPSS 0.009
CVE-2023-33660
A heap buffer overflow vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function copyn_str() in the file mqtt_parser.c. An attacker could exploit this vulnerability to cause a denial of service attack.
Published 2023-06-08 · Modified
7.5EPSS 0.012
CVE-2023-33658
A heap buffer overflow vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function nni_msg_get_pub_pid() in the file message.c. An attacker could exploit this vulnerability to cause a denial of service attack.
Published 2023-06-08 · Modified
7.5EPSS 0.012
CVE-2023-33659
A heap buffer overflow vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function nmq_subinfo_decode() in the file mqtt_parser.c. An attacker could exploit this vulnerability to cause a denial of service attack.
Published 2023-06-06 · Modified
7.5EPSS 0.011
CVE-2023-33657
A use-after-free vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function nni_mqtt_msg_get_publish_property() in the file mqtt_msg.c. This vulnerability is caused by improper data tracing, and an attacker could exploit it to cause a denial of service attack.
Published 2023-06-08 · Modified
7.5EPSS 0.010
CVE-2023-29996
In NanoMQ v0.15.0-0, segment fault with Null Pointer Dereference occurs in the process of decoding subinfo_decode and unsubinfo_decode.
Published 2023-05-04 · Modified
7.5EPSS 0.008
CVE-2023-29994
In NanoMQ v0.15.0-0, Heap overflow occurs in read_byte function of mqtt_code.c.
Published 2023-05-04 · Modified
7.5EPSS 0.007
CVE-2023-29995
In NanoMQ v0.15.0-0, a Heap overflow occurs in copyn_utf8_str function of mqtt_parser.c
Published 2023-05-04 · Modified
7.5EPSS 0.007
CVE-2023-34494
NanoMQ 0.16.5 is vulnerable to heap-use-after-free in the nano_ctx_send function of nmq_mqtt.c.
Published 2023-06-12 · Modified
7.5EPSS 0.007
CVE-2026-25627
nanomq: OOB Read / Crash (DoS) via Malformed MQTT Remaining Length over WebSocket
Published 2026-03-30 · Analyzed
7.5EPSS 0.006
CVE-2026-36590
An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qos_db_set function in broker_tcp.c component
Published 2026-07-15 · Analyzed
7.5EPSS 0.006
CVE-2024-42650
NanoMQ 0.17.5 was discovered to contain a segmentation fault via the component /nanomq/pub_handler.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PUBLISH message.
Published 2025-07-15 · Analyzed
7.5EPSS 0.006
CVE-2026-32696
NanoMQ HTTP Auth: Missing username/password can trigger a NULL-pointer strlen() in auth_http.c:set_data(), causing a process crash — SIGSEGV, remotely triggerable
Published 2026-03-30 · Analyzed
7.5EPSS 0.006
CVE-2024-31041
Null Pointer Dereference vulnerability in topic_filtern function in mqtt_parser.c in NanoMQ 0.21.7 allows attackers to cause a denial of service.
Published 2024-04-17 · Analyzed
7.5EPSS 0.006
CVE-2024-44460
An invalid read size in Nanomq v0.21.9 allows attackers to cause a Denial of Service (DoS).
Published 2024-09-12 · Modified
7.5EPSS 0.005
CVE-2024-42651
NanoMQ v0.17.9 was discovered to contain a heap use-after-free vulnerability via the component sub_Ctx_handle. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SUBSCRIBE message.
Published 2025-07-29 · Analyzed
7.5EPSS 0.004
CVE-2024-42646
A segmentation fault in NanoMQ v0.21.10 allows attackers to cause a Denial of Service (DoS) via crafted messages.
Published 2025-07-14 · Modified
7.5EPSS 0.004
CVE-2025-59946
NanoMQ has a Use After Free vulnerability via sub info list
Published 2025-12-27 · Analyzed
7.5EPSS 0.004
CVE-2024-48077
NanoMQ v0.22.7 is vulnerable to Denial of Service (DoS) due to improper resource throttling. A crafted sequence of requests causes the recv-q queue to saturate, leading to the rapid exhaustion of system file descriptors (FDs). This exhaustion triggers a process crash, rendering the broker unable to provide services.
Published 2026-01-15 · Modified
7.5EPSS 0.004
CVE-2026-21888
MQTT v5 Variable Byte Integer parsing out-of-bounds: get_var_integer()
Published 2026-03-11 · Analyzed
7.5EPSS 0.003
CVE-2025-66023
NanoMQ has Use-After-Free of malformed bridging message
Published 2026-01-01 · Analyzed
6.9EPSS 0.004
CVE-2024-31036
A heap-buffer-overflow vulnerability in the read_byte function in NanoMQ v.0.21.7 allows attackers to cause a denial of service via transmission of crafted hexstreams.
Published 2024-04-22 · Analyzed
6.8EPSS 0.003
CVE-2024-25767
nanomq 0.21.2 contains a Use-After-Free vulnerability in /nanomq/nng/src/core/socket.c.
Published 2024-02-26 · Analyzed
6.5EPSS 0.006
CVE-2024-42648
NanoMQ v0.22.10 was discovered to contain a heap overflow which allows attackers to cause a Denial of Service (DoS) via a crafted CONNECT message.
Published 2025-07-14 · Modified
6.5EPSS 0.003
CVE-2024-42649
NanoMQ v0.22.10 was discovered to contain a memory leak which allows attackers to cause a Denial of Service (DoS) via a crafted PUBLISH message.
Published 2025-07-14 · Modified
6.5EPSS 0.003
CVE-2025-68699
NanoMQ $share/ Subscription Validation and Forwarding Parsing Inconsistency: NULL Pointer Increment Causes Crash
Published 2026-02-04 · Analyzed
6.5EPSS 0.003
CVE-2023-33656
A memory leak vulnerability exists in NanoMQ 0.17.2. The vulnerability is located in the file message.c. An attacker could exploit this vulnerability to cause a denial of service attack by causing the program to consume all available memory resources.
Published 2023-05-30 · Modified
5.5EPSS 0.004
CVE-2026-22040
NanoMQ 0.24.6 Use-After-Free Leading to Heap Corruption and Broker Crash
Published 2026-03-04 · Analyzed
5.3EPSS 0.002
CVE-2024-31040
Buffer Overflow vulnerability in the get_var_integer function in mqtt_parser.c in NanoMQ 0.21.7 allows remote attackers to cause a denial of service via a series of specially crafted hexstreams.
Published 2024-04-17 · Analyzed
2.7EPSS 0.006