Impact
An improper handling of malformed UNSUBSCRIBE packets in the NanoMQ MQTT broker causes an infinite loop during decoding. The nni_mqtt_msg_decode_unsubscribe() function fails to abort when 'read_uint16()' returns a failure while counting topics. A zero‑length topic with trailing data leaves the read buffer position unchanged while the topic counter increments. This leads to an unbounded loop that consumes CPU and memory, and forces the broker to repeatedly block the client.
Affected Systems
Vulnerable is the NanoMQ MQTT broker, versions older than 0.24.14. Attackers need to send a specifically crafted UNSUBSCRIBE packet to a broker that accepts MQTT 3.1.1 connections. The flaw affects only the broker side decoding of unsubscription requests; downstream database handling is not impacted.
Risk and Exploitability
With a CVSS score of 2, the vulnerability is rated low severity, and the EPSS score is <1% while the vulnerability is not listed in the CISA KEV catalog. The exploit requires remote control of a MQTT broker that processes malformed packets from a client. Because the issue builds up client memory usage during reconnection, an attacker who can cause a client to repeatedly reconnect to the broker could drain resources and trigger a denial‑of‑service.
OpenCVE Enrichment