PT-2026-29116 · Nanomq · Nanomq

Grant-Yim

·

Published

2026-03-30

·

Updated

2026-03-31

·

CVE-2026-25627

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions NanoMQ versions prior to 0.24.8
Description NanoMQ MQTT Broker is an Edge Messaging Platform. Before version 0.24.8, the MQTT-over-WebSocket transport in NanoMQ could be crashed by sending an MQTT packet with a deliberately large Remaining Length in the fixed header while providing a much shorter actual payload. The code copies bytes of the Remaining Length without verifying that the current receive buffer contains that many bytes, resulting in an out-of-bounds read. This can be triggered remotely through the WebSocket listener.
Recommendations Update NanoMQ to version 0.24.8 or later.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-25627
GHSA-W4RH-V3H2-J29X

Affected Products

Nanomq