VendorsEMQXnanomqany version
Vulnerabilities

EMQX EMQ Technologies NanoMQ any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2025-59947
NanoMQ has Buffer Overflow
Published 2025-12-15 · Analyzed
9.0EPSS 0.003
CVE-2026-34608
nanomq: Heap-Buffer-Overflow in webhook_inproc.c via cJSON_Parse OOB Read
Published 2026-04-02 · Analyzed
8.2EPSS 0.006
CVE-2026-32135
NanoMQ has Heap Buffer Overflow in URI Parameter Parsing
Published 2026-04-20 · Analyzed
7.7EPSS 0.009
CVE-2026-25627
nanomq: OOB Read / Crash (DoS) via Malformed MQTT Remaining Length over WebSocket
Published 2026-03-30 · Analyzed
7.5EPSS 0.006
CVE-2026-32696
NanoMQ HTTP Auth: Missing username/password can trigger a NULL-pointer strlen() in auth_http.c:set_data(), causing a process crash — SIGSEGV, remotely triggerable
Published 2026-03-30 · Analyzed
7.5EPSS 0.006
CVE-2025-59946
NanoMQ has a Use After Free vulnerability via sub info list
Published 2025-12-27 · Analyzed
7.5EPSS 0.004
CVE-2026-21888
MQTT v5 Variable Byte Integer parsing out-of-bounds: get_var_integer()
Published 2026-03-11 · Analyzed
7.5EPSS 0.003
CVE-2025-66023
NanoMQ has Use-After-Free of malformed bridging message
Published 2026-01-01 · Analyzed
6.9EPSS 0.004
CVE-2026-22040
NanoMQ 0.24.6 Use-After-Free Leading to Heap Corruption and Broker Crash
Published 2026-03-04 · Analyzed
5.3EPSS 0.002