CVE-2026-32696 identifies a denial-of-service vulnerability in NanoMQ MQTT Broker version 0.24.6. This flaw, a NULL pointer dereference (CWE-476), occurs when HTTP authentication is enabled with specific username/password placeholders (%u/%P) and a client connects without providing credentials, leading to a remote crash. Rated with a CVSS 3.1 score of 3.1 (LOW), its exploitation requires a high attack complexity due to specific configuration prerequisites. There is currently no evidence of active exploitation, public exploit code, or significant community discussion regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.24.7CPE matchmatch criteria | cpe:2.3:a:emqx:nanomq:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.