Impact
NanoMQ's broker-side MQTT v5 parser contains a heap buffer overflow in the nmq_subinfo_decode() routine, triggered by a crafted SUBSCRIBE packet with a multi-byte Properties Length and repeated Subscription Identifiers. The parsing error causes get_var_integer() to read past the end of the heap buffer, leading to a broker crash. The flaw is a pure availability issue; it does not enable code execution or privilege escalation.
Affected Systems
All NanoMQ releases prior to version 0.24.14, including 0.24.13 and earlier, are affected. The vulnerability was fixed in the 0.24.14 release and subsequent patches.
Risk and Exploitability
The CVSS score of 7 indicates a high severity for availability. The EPSS score of less than 1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote MQTT client that can connect to the broker; this inference is made from the description that the flaw is reachable through the broker receive path and requires no special broker-side privileges. An attacker could repeatedly send malformed SUBSCRIBE packets to cause the broker to crash, resulting in downtime until the broker is restarted.
OpenCVE Enrichment