PT-2025-51314 · Nanomq · Nanomq

CVE-2025-59947

·

Published

2025-12-15

·

Updated

2025-12-21

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NanoMQ versions prior to 0.24.4
Description NanoMQ is a messaging broker/bus designed for IoT Edge and SDV environments. A buffer overflow can occur when processing PUBLISH packets that trigger both shared and standard subscriptions. This issue impacts versions prior to 0.24.4. As a temporary measure, disabling shared subscriptions can mitigate the risk.
Recommendations Update to version 0.24.4 or later. Disable shared subscriptions as a workaround for versions prior to 0.24.4.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-59947
GHSA-98F4-CMG8-X7F3

Affected Products

Nanomq