nanomq has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 3.7 (low).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 3.7
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
nanomq vulnerabilities
CVEs affecting nanomq, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-44639Low· 3.7PoCNanoMQ is an MQTT broker
NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's MQTT v5 property decoder in nng/src/supplemental/mqtt/mqtt_codec.c uses property_append() to walk the entire linked list for each property added by decode_buf_properties(). A remote un…
CVE-2026-73863High· 7.0NanoMQ is an MQTT broker
NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's broker-side MQTT v5 nmq_subinfo_decode() function in nng/src/sp/protocol/mqtt/mqtt_parser.c reuses len_of_varint from the outer Properties Length while parsing each SUBSCRIPTION_IDENTI…
CVE-2026-61633Low· 2.0PoCNanoMQ is an MQTT broker
NanoMQ is an MQTT broker. Prior to 0.24.14, the NanoMQ client function nni_mqtt_msg_decode_unsubscribe() in nng/src/supplemental/mqtt/mqtt_codec.c does not handle a failed read_uint16() while counting topics in a malformed UNSUBSCRIBE pa…