CVE-2026-32696

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In NanoMQ version 0.24.6, after enabling auth.http_auth (HTTP authentication), when a client connects to the broker using MQTT CONNECT without providing username/password, and the configuration params uses the placeholders %u / %P (e.g., username="%u", password="%P"), the HTTP request construction phase enters auth_http.c:set_data(). This results in calling strlen() on a NULL pointer, causing a SIGSEGV crash. This crash can be triggered remotely, resulting in a denial of service. This issue has been patched in version 0.24.7.
Configurations

Configuration 1 (hide)

cpe:2.3:a:emqx:nanomq:*:*:*:*:*:*:*:*

History

13 Apr 2026, 14:07

Type Values Removed Values Added
First Time Emqx
Emqx nanomq
CPE cpe:2.3:a:emqx:nanomq:*:*:*:*:*:*:*:*
References () https://github.com/nanomq/NanoNNG/commit/c20aa27e5290bb480a5315099952480d35f37a8b - () https://github.com/nanomq/NanoNNG/commit/c20aa27e5290bb480a5315099952480d35f37a8b - Patch
References () https://github.com/nanomq/NanoNNG/pull/1394 - () https://github.com/nanomq/NanoNNG/pull/1394 - Issue Tracking, Patch
References () https://github.com/nanomq/nanomq/releases/tag/0.24.7 - () https://github.com/nanomq/nanomq/releases/tag/0.24.7 - Product, Release Notes
References () https://github.com/nanomq/nanomq/security/advisories/GHSA-77f4-wvq8-mp3p - () https://github.com/nanomq/nanomq/security/advisories/GHSA-77f4-wvq8-mp3p - Exploit, Vendor Advisory

01 Apr 2026, 14:24

Type Values Removed Values Added
Summary
  • (es) NanoMQ MQTT Broker (NanoMQ) es una plataforma de mensajería Edge integral. En la versión 0.24.6 de NanoMQ, después de habilitar auth.http_auth (autenticación HTTP), cuando un cliente se conecta al broker usando MQTT CONNECT sin proporcionar nombre de usuario/contraseña, y los parámetros de configuración usan los marcadores de posición %u / %P (por ejemplo, username='%u', password='%P'), la fase de construcción de la solicitud HTTP entra en auth_http.c:set_data(). Esto resulta en la llamada a strlen() sobre un puntero NULL, causando un fallo SIGSEGV. Este fallo puede ser activado remotamente, resultando en una denegación de servicio. Este problema ha sido parcheado en la versión 0.24.7.

30 Mar 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-30 21:17

Updated : 2026-06-17 10:36


NVD link : CVE-2026-32696

Mitre link : CVE-2026-32696

CVE.ORG link : CVE-2026-32696


JSON object : View

Products Affected

emqx

  • nanomq
CWE
CWE-476

NULL Pointer Dereference