Description
NanoMQ is an MQTT broker. Prior to 0.24.14, the NanoMQ client function nni_mqtt_msg_decode_unsubscribe() in nng/src/supplemental/mqtt/mqtt_codec.c does not handle a failed read_uint16() while counting topics in a malformed UNSUBSCRIBE packet. A zero-length topic followed by trailing data can leave buf.curpos unchanged while topic_count continues to increase, allowing a malicious MQTT broker to hang a connecting MQTT 3.1.1 client, consume CPU and memory, and repeatedly deny service when automatic reconnection is enabled. The broker-side nmq_unsubinfo_decode path is not affected. This issue is fixed in version 0.24.14.
Published: 2026-09-18
Score: 2 Low
EPSS: < 1% Very Low
KEV: No
Impact: Remote Denial of Service
Action: Apply Patch
AI Analysis

Impact

An improper handling of malformed UNSUBSCRIBE packets in the NanoMQ MQTT broker causes an infinite loop during decoding. The nni_mqtt_msg_decode_unsubscribe() function fails to abort when 'read_uint16()' returns a failure while counting topics. A zero‑length topic with trailing data leaves the read buffer position unchanged while the topic counter increments. This leads to an unbounded loop that consumes CPU and memory, and forces the broker to repeatedly block the client.

Affected Systems

Vulnerable is the NanoMQ MQTT broker, versions older than 0.24.14. Attackers need to send a specifically crafted UNSUBSCRIBE packet to a broker that accepts MQTT 3.1.1 connections. The flaw affects only the broker side decoding of unsubscription requests; downstream database handling is not impacted.

Risk and Exploitability

With a CVSS score of 2, the vulnerability is rated low severity, and the EPSS score is <1% while the vulnerability is not listed in the CISA KEV catalog. The exploit requires remote control of a MQTT broker that processes malformed packets from a client. Because the issue builds up client memory usage during reconnection, an attacker who can cause a client to repeatedly reconnect to the broker could drain resources and trigger a denial‑of‑service.

Generated by OpenCVE AI on September 19, 2026 at 16:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update NanoMQ to version 0.24.14 or newer to fix the decoder loop bug.
  • On client applications that connect to the broker, disable automatic reconnection or configure a back‑off strategy so that a stalled connection does not repeatedly consume broker resources during a denial‑of‑service.
  • Monitor broker CPU and memory usage, and temporarily block IP addresses that repeatedly send malformed UNSUBSCRIBE packets while the patch is deployed.

Generated by OpenCVE AI on September 19, 2026 at 16:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Nanomq
Nanomq nanomq
Vendors & Products Nanomq
Nanomq nanomq

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description NanoMQ is an MQTT broker. Prior to 0.24.14, the NanoMQ client function nni_mqtt_msg_decode_unsubscribe() in nng/src/supplemental/mqtt/mqtt_codec.c does not handle a failed read_uint16() while counting topics in a malformed UNSUBSCRIBE packet. A zero-length topic followed by trailing data can leave buf.curpos unchanged while topic_count continues to increase, allowing a malicious MQTT broker to hang a connecting MQTT 3.1.1 client, consume CPU and memory, and repeatedly deny service when automatic reconnection is enabled. The broker-side nmq_unsubinfo_decode path is not affected. This issue is fixed in version 0.24.14.
Title NanoMQ: Infinite Loop in UNSUBSCRIBE Decoder Leading to Remote DoS
Weaknesses CWE-835
References
Metrics cvssV3_1

{'score': 2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T17:26:49.956Z

Reserved: 2026-07-10T17:38:57.111Z

Link: CVE-2026-61633

cve-icon Vulnrichment

Updated: 2026-09-18T17:26:42.861Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T17:16:58.340

Modified: 2026-09-18T18:17:09.433

Link: CVE-2026-61633

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T17:00:12Z

Weaknesses
  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')