NanoMQ MQTT Broker versions prior to 0.24.11 contain a remotely triggerable heap buffer overflow vulnerability in the REST API's uri_param_parse function. The flaw stems from an off-by-one memory allocation error that permits attackers to write a null byte beyond allocated buffer boundaries via crafted HTTP requests. This vulnerability affects the NanoMQ Edge Messaging Platform used in IoT and edge computing environments. The vulnerability carries a CVSS 3.1 score of 7.5 (HIGH) with a network-based attack vector requiring no authentication or user interaction, making it easily exploitable by remote unauthenticated actors. While the impact is limited to denial of service through availability disruption, the attack requires no special privileges or preconditions. The low environmental EPSS score of 0.00145 indicates minimal relative risk compared to the broader CVE landscape. There is no evidence of active exploitation in the wild, and the vulnerability is not currently tracked on the CISA Known Exploited Vulnerabilities list. The issue remains inactive on exploit availability tracking systems. Organizations running NanoMQ should prioritize upgrading to version 0.24.11 or later, though the absence of public exploit code and active exploitation suggests moderate time flexibility in patch deployment.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.24.11CPE matchmatch criteria | cpe:2.3:a:emqx:nanomq:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.