PT-2025-51314 · Nanomq · Nanomq

Published

2025-12-15

·

Updated

2025-12-21

·

CVE-2025-59947

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NanoMQ versions prior to 0.24.4
Description NanoMQ is a messaging broker/bus designed for IoT Edge and SDV environments. A buffer overflow can occur when processing PUBLISH packets that trigger both shared and standard subscriptions. This issue impacts versions prior to 0.24.4. As a temporary measure, disabling shared subscriptions can mitigate the risk.
Recommendations Update to version 0.24.4 or later. Disable shared subscriptions as a workaround for versions prior to 0.24.4.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2025-59947
GHSA-98F4-CMG8-X7F3

Affected Products

Nanomq