Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

nanomq — Vulnerabilities & Security Advisories 17

Browse all 17 CVE security advisories affecting nanomq. AI-powered Chinese analysis, POCs, and references for each vulnerability.

NanoMQ is an ultra-lightweight MQTT broker designed for IoT and edge computing environments, handling high-volume message routing with minimal resource consumption. Historically, it has been susceptible to remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from improper input validation and authentication flaws. While no major public security incidents have been widely documented, the 11 recorded CVEs highlight ongoing concerns around buffer overflows and insecure default configurations. Its lightweight architecture introduces unique attack surfaces, particularly in constrained environments where security updates may be delayed. Organizations should implement strict network segmentation and regular patching to mitigate risks associated with its historically vulnerable components.

Found 17 results / 17Clear Filters
Top products by nanomq: nanomq
CVE IDTitleCVSSSeverityPublished
CVE-2026-47276 NULL Pointer Dereference in REST API properties_parse via Malformed user_properties — nanomqCWE-476 6.5 Medium2026-07-20
CVE-2026-47275 nanomq NULL Pointer Dereference in MQTTv5 Client CONNECT Decoder Leading to Remote DoS — nanomqCWE-476 2.6 Low2026-07-20
CVE-2026-35217 NanoMQ Incorrectly Accepts a Malformed SUBSCRIBE and Can Be Driven into an ASAN-Detectable Out-of-Bounds Read — nanomqCWE-125 6.5 Medium2026-07-20
CVE-2026-45151 NanoMQ: NULL Pointer Dereference — nanomqCWE-476--2026-05-29
CVE-2026-44640 NanoMQ: QUIC Dialer Close Type Confusion — nanomqCWE-843 4.5 Medium2026-05-29
CVE-2026-32134 NanoMQ: NULL Pointer Dereference Crash in tcptran_pipe_peer During Session Restore — nanomqCWE-476 5.9 Medium2026-05-19
CVE-2026-32135 NanoMQ has Heap Buffer Overflow in URI Parameter Parsing — nanomqCWE-122 9.8AICriticalAI2026-04-20
CVE-2026-34608 nanomq: Heap-Buffer-Overflow in webhook_inproc.c via cJSON_Parse OOB Read — nanomqCWE-125 4.9 Medium2026-04-02
CVE-2026-32696 NanoMQ HTTP Auth: Missing username/password can trigger a NULL-pointer strlen() in auth_http.c:set_data(), causing a process crash — SIGSEGV, remotely triggerable — nanomqCWE-476 3.1 Low2026-03-30
CVE-2026-25627 nanomq: OOB Read / Crash (DoS) via Malformed MQTT Remaining Length over WebSocket — nanomqCWE-125 6.5 Medium2026-03-30
CVE-2026-21888 MQTT v5 Variable Byte Integer parsing out-of-bounds: get_var_integer() — nanomqCWE-125 7.5 High2026-03-11
CVE-2026-22040 NanoMQ 0.24.6 Use-After-Free Leading to Heap Corruption and Broker Crash — nanomqCWE-416 5.3 Medium2026-03-04
CVE-2025-68699 NanoMQ $share/ Subscription Validation and Forwarding Parsing Inconsistency: NULL Pointer Increment Causes Crash — nanomqCWE-476 6.5 Medium2026-02-04
CVE-2025-66023 NanoMQ has Use-After-Free of malformed bridging message — nanomqCWE-416 7.5 -2026-01-01
CVE-2025-59946 NanoMQ has a Use After Free vulnerability via sub info list — nanomqCWE-416 7.5 High2025-12-27
CVE-2025-59947 NanoMQ has Buffer Overflow — nanomqCWE-120 9.8AICriticalAI2025-12-15
CVE-2025-65953 NanoMQ UAF of retain message due to invalid MQTTV5 properties — nanomqCWE-416 7.5AIHighAI2025-11-25

This page lists every published CVE security advisory associated with nanomq. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.