Impact
NanoMQ’s MQTT v5 property decoder performs O(N²) linked‑list insertions for each User Property in a packet. A remote, unauthenticated client can send a PUBLISH or SUBSCRIBE message containing many User Properties, exhausting CPU resources and rendering the broker unresponsive. Persistently sending such packets can maintain the DoS condition. The weakness is identified as CWE‑407, reflecting inefficient algorithmic complexity.
Affected Systems
This flaw affects the NanoMQ MQTT broker (nanomq:nanomq) versions prior to 0.24.14. The advisory recommends upgrading to version 0.24.14 or later to apply the fix that corrects the property parsing logic.
Risk and Exploitability
The CVSS score is 3.7, indicating a moderate risk. EPSS score is < 1% and the vulnerability is not listed in CISA’s KEV catalog. An attacker can exploit the flaw from anywhere on the network with an unauthenticated MQTT client, triggering a denial of service by sending packets that contain a large number of User Properties. Successful exploitation requires only network access to the broker; no local privileges or additional credentials are needed.
OpenCVE Enrichment