CVE-2026-45151

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In 0.24.8 and earlier, quic_stream_recv can dereference a null substream pointer when a substream is in reopen state. The code finishes the AIO with error but does not return before locking c->mtx.
CVSS

No CVSS.

Configurations

No configuration.

History

22 Jul 2026, 06:10

Type Values Removed Values Added
Summary
  • (es) NanoMQ MQTT Broker (NanoMQ) es una Plataforma de Mensajería de Borde integral. En 0.24.8 y anteriores, quic_stream_recv puede desreferenciar un puntero de subflujo nulo cuando un subflujo está en estado de reapertura. El código finaliza la AIO con error pero no retorna antes de bloquear c->mtx.

01 Jun 2026, 15:16

Type Values Removed Values Added
References () https://github.com/nanomq/nanomq/security/advisories/GHSA-9qhf-wgp4-p7w5 - () https://github.com/nanomq/nanomq/security/advisories/GHSA-9qhf-wgp4-p7w5 -

29 May 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-29 20:16

Updated : 2026-07-22 06:10


NVD link : CVE-2026-45151

Mitre link : CVE-2026-45151

CVE.ORG link : CVE-2026-45151


JSON object : View

Products Affected

No product.

CWE
CWE-476

NULL Pointer Dereference