CVE-2026-44640

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to 0.24.14, aio->prov_data is stored as nni_quic_conn* during dialing, but read as ex_quic_conn* during dialer close. This type confusion causes invalid object interpretation and leads to close-path hang/crash behavior. This vulnerability is fixed in 0.24.14.
Configurations

No configuration.

History

29 May 2026, 22:16

Type Values Removed Values Added
References () https://github.com/nanomq/nanomq/security/advisories/GHSA-9fgw-v323-jmjj - () https://github.com/nanomq/nanomq/security/advisories/GHSA-9fgw-v323-jmjj -

29 May 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-29 20:16

Updated : 2026-05-29 22:16


NVD link : CVE-2026-44640

Mitre link : CVE-2026-44640

CVE.ORG link : CVE-2026-44640


JSON object : View

Products Affected

No product.

CWE
CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')