PT-2026-29123 · Nanomq · Nanomq

Lowjaylinyu

·

Publicado

2026-03-30

·

Atualizado

2026-03-31

·

CVE-2026-32696

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions NanoMQ versions prior to 0.24.7
Description NanoMQ MQTT Broker is an Edge Messaging Platform. When HTTP authentication is enabled (auth.http auth) in NanoMQ version 0.24.6, a client connecting via MQTT CONNECT without username/password, and with configuration parameters using placeholders %u and %P (e.g., username="%u", password="%P"), triggers a crash. This occurs because the set data() function in auth http.c calls strlen() on a NULL pointer, resulting in a SIGSEGV crash. This crash can be triggered remotely, leading to a denial of service.
Recommendations Upgrade to NanoMQ version 0.24.7 or later.

Exploit

Correção

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-32696
GHSA-77F4-WVQ8-MP3P

Produtos afetados

Nanomq