Heap Memory Corruption in NanoMQ MQTT Broker by NanoMQ
CVE-2026-22040
5.3MEDIUM
What is CVE-2026-22040?
The NanoMQ MQTT Broker version 0.24.6 is susceptible to a heap memory corruption vulnerability that can be exploited through a specific traffic pattern. By generating high-frequency publishing activities alongside rapid client reconnections using the same ClientID and overwhelming subscribe/unsubscribe activities, attackers can trigger a destabilizing event in the broker process. This leads to an immediate exit of the broker process with a SIGABRT signal due to invalid pointer reference during memory deallocation. As of the latest information, no patched versions are available, necessitating immediate attention from all users of the affected release.
Affected Version(s)
nanomq = 0.24.6
