Heap Memory Corruption in NanoMQ MQTT Broker by NanoMQ
CVE-2026-22040

5.3MEDIUM

Key Information:

Vendor

NanoMQ

Status
Vendor
CVE Published:
4 March 2026

What is CVE-2026-22040?

The NanoMQ MQTT Broker version 0.24.6 is susceptible to a heap memory corruption vulnerability that can be exploited through a specific traffic pattern. By generating high-frequency publishing activities alongside rapid client reconnections using the same ClientID and overwhelming subscribe/unsubscribe activities, attackers can trigger a destabilizing event in the broker process. This leads to an immediate exit of the broker process with a SIGABRT signal due to invalid pointer reference during memory deallocation. As of the latest information, no patched versions are available, necessitating immediate attention from all users of the affected release.

Affected Version(s)

nanomq = 0.24.6

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.