PT-2026-95485 · Nanomq · Nanomq

CVE-2026-44639

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions NanoMQ versions prior to 0.24.14
Description The MQTT v5 property decoder in the nng/src/supplemental/mqtt/mqtt codec.c file uses the property append() function to traverse a linked list for every property added by decode buf properties(). A remote unauthenticated client can send PUBLISH or SUBSCRIBE packets containing a large number of User Properties, triggering O(N²) linked-list insertion and excessive CPU consumption. This results in the broker becoming unresponsive, and the denial of service can be sustained through repeated packets.
Recommendations Update to version 0.24.14.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44639
GHSA-6MWG-445V-2QRV

Affected Products

Nanomq