Description
NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's broker-side MQTT v5 nmq_subinfo_decode() function in nng/src/sp/protocol/mqtt/mqtt_parser.c reuses len_of_varint from the outer Properties Length while parsing each SUBSCRIPTION_IDENTIFIER. A remote client can send a SUBSCRIBE packet with a multi-byte Properties Length and repeated subscription identifiers, causing get_var_integer() to begin at an incorrect offset and read beyond the heap message buffer. The flaw is reachable through the broker receive path and can crash the broker, while the separately reported topic-option off-by-one occurs later and is not this vulnerability. This issue is fixed in version 0.24.14.
Published: 2026-09-18
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (Broker Crash)
Action: Patch Now
AI Analysis

Impact

NanoMQ's broker-side MQTT v5 parser contains a heap buffer overflow in the nmq_subinfo_decode() routine, triggered by a crafted SUBSCRIBE packet with a multi-byte Properties Length and repeated Subscription Identifiers. The parsing error causes get_var_integer() to read past the end of the heap buffer, leading to a broker crash. The flaw is a pure availability issue; it does not enable code execution or privilege escalation.

Affected Systems

All NanoMQ releases prior to version 0.24.14, including 0.24.13 and earlier, are affected. The vulnerability was fixed in the 0.24.14 release and subsequent patches.

Risk and Exploitability

The CVSS score of 7 indicates a high severity for availability. The EPSS score of less than 1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote MQTT client that can connect to the broker; this inference is made from the description that the flaw is reachable through the broker receive path and requires no special broker-side privileges. An attacker could repeatedly send malformed SUBSCRIBE packets to cause the broker to crash, resulting in downtime until the broker is restarted.

Generated by OpenCVE AI on September 19, 2026 at 17:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade NanoMQ to version 0.24.14 or later to eliminate the heap overflow bug
  • Deploy the patched broker version to all production and test environments immediately
  • As an interim measure, restrict external MQTT client access or enable client authentication to reduce exposure to malformed packets while upgrades are performed

Generated by OpenCVE AI on September 19, 2026 at 17:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Nanomq
Nanomq nanomq
Vendors & Products Nanomq
Nanomq nanomq

Fri, 18 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's broker-side MQTT v5 nmq_subinfo_decode() function in nng/src/sp/protocol/mqtt/mqtt_parser.c reuses len_of_varint from the outer Properties Length while parsing each SUBSCRIPTION_IDENTIFIER. A remote client can send a SUBSCRIBE packet with a multi-byte Properties Length and repeated subscription identifiers, causing get_var_integer() to begin at an incorrect offset and read beyond the heap message buffer. The flaw is reachable through the broker receive path and can crash the broker, while the separately reported topic-option off-by-one occurs later and is not this vulnerability. This issue is fixed in version 0.24.14.
Title NanoMQ: Heap-Buffer-Overflow in `nmq_subinfo_decode()` During MQTT v5 SUBSCRIBE Parsing
Weaknesses CWE-125
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-24T20:59:45.777Z

Reserved: 2026-08-13T17:44:28.646Z

Link: CVE-2026-73863

cve-icon Vulnrichment

Updated: 2026-09-24T20:59:43.373Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T17:17:00.020

Modified: 2026-09-24T21:18:35.913

Link: CVE-2026-73863

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T17:15:04Z

Weaknesses