PT-2026-29116 · Nanomq · Nanomq
Grant-Yim
·
Published
2026-03-30
·
Updated
2026-03-31
·
CVE-2026-25627
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
NanoMQ versions prior to 0.24.8
Description
NanoMQ MQTT Broker is an Edge Messaging Platform. Before version 0.24.8, the MQTT-over-WebSocket transport in NanoMQ could be crashed by sending an MQTT packet with a deliberately large Remaining Length in the fixed header while providing a much shorter actual payload. The code copies bytes of the Remaining Length without verifying that the current receive buffer contains that many bytes, resulting in an out-of-bounds read. This can be triggered remotely through the WebSocket listener.
Recommendations
Update NanoMQ to version 0.24.8 or later.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nanomq