PT-2026-95493 · Nanomq · Nanomq
CVE-2026-73863
·
Published
2026-09-18
·
Updated
2026-09-18
CVSS v4.0
7.0
High
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:H |
Name of the Vulnerable Software and Affected Versions
NanoMQ versions prior to 0.24.14
Description
The broker-side MQTT v5
nmq subinfo decode() function in nng/src/sp/protocol/mqtt/mqtt parser.c reuses len of varint from the outer Properties Length when parsing each SUBSCRIPTION IDENTIFIER. A remote client can send a SUBSCRIBE packet containing a multi-byte Properties Length and repeated subscription identifiers. This causes the get var integer() function to start at an incorrect offset and read beyond the heap message buffer, which can lead to a broker crash.Recommendations
Update to version 0.24.14.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nanomq