CVE-2026-25627

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.8, NanoMQ’s MQTT-over-WebSocket transport can be crashed by sending an MQTT packet with a deliberately large Remaining Length in the fixed header while providing a much shorter actual payload. The code path copies Remaining Length bytes without verifying that the current receive buffer contains that many bytes, resulting in an out-of-bounds read (ASAN reports OOB / crash). This is remotely triggerable over the WebSocket listener. This issue has been patched in version 0.24.8.
Configurations

Configuration 1 (hide)

cpe:2.3:a:emqx:nanomq:*:*:*:*:*:*:*:*

History

02 Apr 2026, 15:33

Type Values Removed Values Added
References () https://github.com/nanomq/NanoNNG/commit/e80b30bad6d855593a68d18f2785bfaca6faf09e - () https://github.com/nanomq/NanoNNG/commit/e80b30bad6d855593a68d18f2785bfaca6faf09e - Patch
References () https://github.com/nanomq/NanoNNG/pull/1405 - () https://github.com/nanomq/NanoNNG/pull/1405 - Issue Tracking, Patch
References () https://github.com/nanomq/nanomq/releases/tag/0.24.8 - () https://github.com/nanomq/nanomq/releases/tag/0.24.8 - Release Notes
References () https://github.com/nanomq/nanomq/security/advisories/GHSA-w4rh-v3h2-j29x - () https://github.com/nanomq/nanomq/security/advisories/GHSA-w4rh-v3h2-j29x - Exploit, Vendor Advisory
First Time Emqx
Emqx nanomq
CPE cpe:2.3:a:emqx:nanomq:*:*:*:*:*:*:*:*

31 Mar 2026, 20:16

Type Values Removed Values Added
References () https://github.com/nanomq/nanomq/security/advisories/GHSA-w4rh-v3h2-j29x - () https://github.com/nanomq/nanomq/security/advisories/GHSA-w4rh-v3h2-j29x -
Summary
  • (es) NanoMQ MQTT Broker (NanoMQ) es una plataforma de mensajería de borde integral. Antes de la versión 0.24.8, el transporte MQTT-over-WebSocket de NanoMQ puede colapsar al enviar un paquete MQTT con una longitud restante (Remaining Length) deliberadamente grande en la cabecera fija mientras se proporciona una carga útil real mucho más corta. La ruta del código copia bytes de la longitud restante sin verificar que el búfer de recepción actual contenga esa cantidad de bytes, lo que resulta en una lectura fuera de límites (ASAN informa OOB / fallo). Esto puede ser activado remotamente a través del oyente de WebSocket. Este problema ha sido parcheado en la versión 0.24.8.

30 Mar 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-30 21:17

Updated : 2026-06-17 10:24


NVD link : CVE-2026-25627

Mitre link : CVE-2026-25627

CVE.ORG link : CVE-2026-25627


JSON object : View

Products Affected

emqx

  • nanomq
CWE
CWE-125

Out-of-bounds Read