Unrated severityNVD Advisory· Published Mar 4, 2026· Updated Mar 5, 2026
NanoMQ 0.24.6 Use-After-Free Leading to Heap Corruption and Broker Crash
CVE-2026-22040
Description
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In version 0.24.6, by generating a combined traffic pattern of high-frequency publishes and rapid reconnect/kick-out using the same ClientID and massive subscribe/unsubscribe jitter, it is possible to reliably trigger heap memory corruption in the Broker process, causing it to exit immediately with SIGABRT due to free(): invalid pointer. As of time of publication, no known patched versions are available.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/nanomq/nanomq/security/advisories/GHSA-v57q-w88m-424rmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.