CVE-2026-34608 is an out-of-bounds read vulnerability affecting NanoMQ MQTT Broker versions prior to 0.24.10. This flaw occurs in the hook_work_cb() function when processing nng messages, where cJSON_Parse() attempts to read beyond the allocated buffer due to a missing null terminator in the message body. Rated Medium severity with a CVSS score of 4.9, this vulnerability has a network attack vector and low attack complexity, but requires high privileges. Successful exploitation could lead to a high impact on availability, potentially causing denial of service. There is currently no evidence of active exploitation, nor is any public exploit code available in Metasploit, Nuclei, or ExploitDB, indicating low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.24.10CPE matchmatch criteria | cpe:2.3:a:emqx:nanomq:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.