Vulnerabilities
Vulnerable Software
Emqx:  >> Nanomq  Security Vulnerabilities
NanoMQ MQTT Broker (NanoMQ) is an Edge Messaging Platform. Prior to version 0.24.2, there is a classical data racing issue about sub info list which could result in heap use after free crash. This issue has been patched in version 0.24.2.
CVSS Score
7.5
EPSS Score
0.003
Published
2025-12-27
NanoMQ is a messaging broker/bus for IoT Edge & SDV. Versions prior to 0.24.4 have a buffer overflow case while the PUBLISH packets trigger both shared subscription and vanila subscription. This is fixed in version 0.24.4. As a workaround, disable shared subscription.
CVSS Score
8.5
EPSS Score
0.003
Published
2025-12-15
An access control issue in NanoMQ v0.21.10 allows attackers to bypass security restrictions and access sensitive system topic messages using MQTT wildcard characters.
CVSS Score
8.8
EPSS Score
0.004
Published
2025-07-29
NanoMQ v0.17.9 was discovered to contain a heap use-after-free vulnerability via the component sub_Ctx_handle. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SUBSCRIBE message.
CVSS Score
7.5
EPSS Score
0.004
Published
2025-07-29
NanoMQ 0.17.5 was discovered to contain a segmentation fault via the component /nanomq/pub_handler.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PUBLISH message.
CVSS Score
7.5
EPSS Score
0.005
Published
2025-07-15
NanoMQ v0.22.10 was discovered to contain a memory leak which allows attackers to cause a Denial of Service (DoS) via a crafted PUBLISH message.
CVSS Score
6.5
EPSS Score
0.003
Published
2025-07-14
A segmentation fault in NanoMQ v0.21.10 allows attackers to cause a Denial of Service (DoS) via crafted messages.
CVSS Score
7.5
EPSS Score
0.004
Published
2025-07-14
NanoMQ v0.22.10 was discovered to contain a heap overflow which allows attackers to cause a Denial of Service (DoS) via a crafted CONNECT message.
CVSS Score
6.5
EPSS Score
0.003
Published
2025-07-14
An invalid read size in Nanomq v0.21.9 allows attackers to cause a Denial of Service (DoS).
CVSS Score
7.5
EPSS Score
0.005
Published
2024-09-12
A heap-buffer-overflow vulnerability in the read_byte function in NanoMQ v.0.21.7 allows attackers to cause a denial of service via transmission of crafted hexstreams.
CVSS Score
6.8
EPSS Score
0.003
Published
2024-04-22


Contact Us

Shodan ® - All rights reserved