Vulnerabilidades en nanomq
20 resultadosAnálisis Vexday
NanoMQ apresenta 14 vulnerabilidades catalogadas, todas de severidade inferior a crítica, com nenhuma sob exploração ativa conhecida. A fraqueza dominante é CWE-416 (use-after-free), padrão típico de software com linguagem de baixo nível, sendo 3 vulnerabilidades publicadas nos últimos 90 dias indicativo de atividade recente no ciclo de correções. O risco permanece moderado e controlável na ausência de exploração em campo.
CVE-2026-32135HIGHNanoMQ has Heap Buffer Overflow in URI Parameter ParsingEPSS 0.5%CVE-2026-25627MEDIUMnanomq: OOB Read / Crash (DoS) via Malformed MQTT Remaining Length over WebSocketEPSS 0.5%CVE-2026-47276MEDIUMNULL Pointer Dereference in REST API properties_parse via Malformed user_propertiesEPSS 0.4%CVE-2026-32134MEDIUMNanoMQ: NULL Pointer Dereference Crash in tcptran_pipe_peer During Session RestoreEPSS 0.4%CVE-2026-32696LOWNanoMQ HTTP Auth: Missing username/password can trigger a NULL-pointer strlen() in auth_http.c:set_data(), causing a process crash — SIGSEGV, remotely triggerableEPSS 0.4%CVE-2025-59946HIGHNanoMQ has a Use After Free vulnerability via sub info listEPSS 0.4%CVE-2025-66023MEDIUMNanoMQ has Use-After-Free of malformed bridging messageEPSS 0.4%CVE-2026-34608MEDIUMnanomq: Heap-Buffer-Overflow in webhook_inproc.c via cJSON_Parse OOB ReadEPSS 0.4%CVE-2026-44639LOWNanoMQ: O(N²) Denial of Service in MQTT v5 Property ParsingEPSS 0.3%CVE-2025-59947HIGHNanoMQ has Buffer OverflowEPSS 0.3%CVE-2026-35217MEDIUMNanoMQ Incorrectly Accepts a Malformed SUBSCRIBE and Can Be Driven into an ASAN-Detectable Out-of-Bounds ReadEPSS 0.3%CVE-2026-21888HIGHMQTT v5 Variable Byte Integer parsing out-of-bounds: get_var_integer()EPSS 0.3%CVE-2026-73863HIGHNanoMQ: Heap-Buffer-Overflow in `nmq_subinfo_decode()` During MQTT v5 SUBSCRIBE ParsingEPSS 0.3%CVE-2025-68699MEDIUMNanoMQ $share/ Subscription Validation and Forwarding Parsing Inconsistency: NULL Pointer Increment Causes CrashEPSS 0.3%CVE-2026-47275LOWnanomq NULL Pointer Dereference in MQTTv5 Client CONNECT Decoder Leading to Remote DoSEPSS 0.3%CVE-2026-61633LOWNanoMQ: Infinite Loop in UNSUBSCRIBE Decoder Leading to Remote DoSEPSS 0.3%CVE-2026-45151LOWNanoMQ: NULL Pointer DereferenceEPSS 0.2%CVE-2026-22040MEDIUMNanoMQ 0.24.6 Use-After-Free Leading to Heap Corruption and Broker CrashEPSS 0.2%CVE-2025-65953MEDIUMNanoMQ UAF of retain message due to invalid MQTTV5 propertiesEPSS 0.2%CVE-2026-44640MEDIUMNanoMQ: QUIC Dialer Close Type ConfusionEPSS 0.1%