PT-2026-95493 · Nanomq · Nanomq

CVE-2026-73863

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v4.0

7.0

High

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:H
Name of the Vulnerable Software and Affected Versions NanoMQ versions prior to 0.24.14
Description The broker-side MQTT v5 nmq subinfo decode() function in nng/src/sp/protocol/mqtt/mqtt parser.c reuses len of varint from the outer Properties Length when parsing each SUBSCRIPTION IDENTIFIER. A remote client can send a SUBSCRIBE packet containing a multi-byte Properties Length and repeated subscription identifiers. This causes the get var integer() function to start at an incorrect offset and read beyond the heap message buffer, which can lead to a broker crash.
Recommendations Update to version 0.24.14.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73863
GHSA-PF97-VM7H-Q84M

Affected Products

Nanomq