CVE-2024-48077

An issue in nanomq v0.22.7 allows attackers to cause a Denial of Service (DoS) via a crafted request. The number of data packets received in the recv-q queue of the Nanomq process continues to increase, causing the nanomq broker to fall into a deadlock and be unable to provide normal services.
Configurations

Configuration 1 (hide)

cpe:2.3:a:emqx:nanomq:0.22.7:*:*:*:*:*:*:*

History

23 Jan 2026, 19:06

Type Values Removed Values Added
CPE cpe:2.3:a:emqx:nanomq:0.22.7:*:*:*:*:*:*:*
References () https://gist.github.com/pengwGit/2379e7a8fe75d09621f7c060db0237c4 - () https://gist.github.com/pengwGit/2379e7a8fe75d09621f7c060db0237c4 - Third Party Advisory
References () https://github.com/nanomq/nanomq - () https://github.com/nanomq/nanomq - Product
First Time Emqx
Emqx nanomq

15 Jan 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-15 20:16

Updated : 2026-01-23 19:06


NVD link : CVE-2024-48077

Mitre link : CVE-2024-48077

CVE.ORG link : CVE-2024-48077


JSON object : View

Products Affected

emqx

  • nanomq
CWE
CWE-400

Uncontrolled Resource Consumption

CWE-833

Deadlock