📦 Nanomq

by Emqx

🔍 What is Nanomq?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-59947

CRITICAL CVSS 9.0 Dec 15, 2025

NanoMQ versions before 0.24.4 contain a buffer overflow vulnerability when PUBLISH packets trigger both shared and vanilla subscriptions simultaneously. This allows attackers to execute arbitrary code...

CVE-2024-48077

HIGH CVSS 7.5 Jan 15, 2026

This vulnerability in NanoMQ allows attackers to cause a denial of service by sending crafted requests that cause the recv-q queue to fill up, leading to deadlock. Any system running the vulnerable Na...

CVE-2025-59946

HIGH CVSS 7.5 Dec 27, 2025

CVE-2025-59946 is a heap use-after-free vulnerability in NanoMQ MQTT broker caused by a data race condition in subscription information handling. This allows attackers to crash the broker service, pot...

CVE-2024-42655

HIGH CVSS 8.8 Jul 29, 2025

An access control vulnerability in NanoMQ v0.21.10 allows attackers to bypass security restrictions and access sensitive system topic messages using MQTT wildcard characters. This affects systems runn...

CVE-2024-42646

HIGH CVSS 7.5 Jul 14, 2025

A segmentation fault vulnerability in NanoMQ v0.21.10 allows attackers to cause Denial of Service (DoS) by sending specially crafted messages. This affects systems running vulnerable versions of NanoM...

CVE-2024-44460

HIGH CVSS 7.5 Sep 12, 2024

CVE-2024-44460 is an out-of-bounds read vulnerability in Nanomq v0.21.9 that allows attackers to trigger a Denial of Service (DoS) by causing the MQTT broker to crash. This affects all systems running...

CVE-2024-31041

HIGH CVSS 7.5 Apr 17, 2024

A null pointer dereference vulnerability in NanoMQ's topic_filtern function allows attackers to crash the MQTT broker by sending specially crafted messages. This affects all systems running vulnerable...

CVE-2023-34494

HIGH CVSS 7.5 Jun 12, 2023

NanoMQ 0.16.5 contains a heap-use-after-free vulnerability in the nano_ctx_send function that allows attackers to potentially execute arbitrary code or cause denial of service. This affects systems ru...

CVE-2023-33657

HIGH CVSS 7.5 Jun 8, 2023

A use-after-free vulnerability in NanoMQ 0.17.2 allows attackers to trigger memory corruption by calling nni_mqtt_msg_get_publish_property(). This can lead to denial of service through application cra...

CVE-2023-33658

HIGH CVSS 7.5 Jun 8, 2023

A heap buffer overflow vulnerability in NanoMQ 0.17.2 allows attackers to trigger denial of service by exploiting the nni_msg_get_pub_pid() function. This affects systems running vulnerable versions o...

CVE-2023-33659

HIGH CVSS 7.5 Jun 6, 2023

A heap buffer overflow vulnerability in NanoMQ 0.17.2 allows attackers to trigger denial of service by exploiting the nmq_subinfo_decode() function. This affects systems running vulnerable versions of...

CVE-2023-29994

HIGH CVSS 7.5 May 4, 2023

A heap overflow vulnerability in NanoMQ's read_byte function allows attackers to write beyond allocated memory boundaries. This affects all systems running vulnerable versions of NanoMQ, potentially l...

CVE-2023-29996

HIGH CVSS 7.5 May 4, 2023

A null pointer dereference vulnerability in NanoMQ v0.15.0-0 causes segmentation faults when processing malformed MQTT subscription/unsubscription packets. This allows remote attackers to crash the Na...

CVE-2025-68699

MEDIUM CVSS 6.5 Feb 4, 2026

CVE-2025-68699 is a NULL pointer dereference vulnerability in NanoMQ MQTT Broker that allows remote attackers to crash the broker by sending a malformed shared subscription topic. This affects all sys...

CVE-2024-42649

MEDIUM CVSS 6.5 Jul 14, 2025

NanoMQ v0.22.10 contains a memory leak vulnerability in its MQTT PUBLISH message handling. Attackers can send crafted PUBLISH messages to gradually consume system memory, eventually causing a Denial o...