Emqx develops a focused set of message-oriented middleware and IoT connectivity products—including EMQX, NanoMQ, Neuron, and CocoaMQTT—that serve as message brokers and protocol bridges for distributed systems and edge deployments. While the product line remains narrow, these components occupy a prominent role in IoT and real-time messaging architectures where they handle untrusted network input and manage memory-intensive connection state. The vulnerability profile reflects the memory-safety demands inherent to these systems: recurrent exposure centers on buffer-overflow conditions, out-of-bounds read and write operations, and use-after-free flaws that arise from parsing and session-management complexity. A meaningful share of disclosed vulnerabilities reach serious severity, consistent with the remote-accessible nature of message brokers. Defenders should monitor this vendor's releases closely for deployments exposed to external networks or handling sensitive IoT data; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Emqx over time
Signals from CVEs in this vendor scope (41 CVEs).
41 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-36590HIGH An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qos_db_set function in broker_tcp.c component | Jul 15, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-34608HIGH NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.10, in NanoMQ's webhook_inproc.c, the hook_work_cb() function processes nng messages by | Apr 2, 2026 | 8.2 | 30 | NO | NO |
CVE-2026-32696HIGH NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In NanoMQ version 0.24.6, after enabling auth.http_auth (HTTP authentication), when a client connects to the b | Mar 30, 2026 | 7.5 | 29 | NO | NO |
CVE-2024-10964CRITICAL A vulnerability classified as critical has been found in emqx neuron up to 2.10.0. Affected is the function handle_add_plugin in the library cmd.library of the file plugins/restful | Nov 7, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-48077HIGH NanoMQ v0.22.7 is vulnerable to Denial of Service (DoS) due to improper resource throttling. A crafted sequence of requests causes the recv-q queue to saturate, leading to the rapi | Jan 15, 2026 | 7.5 | 28 | NO | NO |
CVE-2025-59947CRITICAL NanoMQ is a messaging broker/bus for IoT Edge & SDV. Versions prior to 0.24.4 have a buffer overflow case while the PUBLISH packets trigger both shared subscription and vanila subs | Dec 15, 2025 | 9.0 | 28 | NO | NO |
CVE-2024-42655HIGH An access control issue in NanoMQ v0.21.10 allows attackers to bypass security restrictions and access sensitive system topic messages using MQTT wildcard characters. | Jul 29, 2025 | 8.8 | 28 | NO | NO |
CVE-2026-32135HIGH NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.11 have a remotely triggerable heap buffer overflow in the `uri_param_parse` function o | Apr 20, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-21888HIGH NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. MQTT v5 Variable Byte Integer parsing out-of-bounds: get_var_integer() accepts 5-byte varints without bounds c | Mar 11, 2026 | 7.5 | 25 | NO | NO |
CVE-2025-59946HIGH NanoMQ MQTT Broker (NanoMQ) is an Edge Messaging Platform. Prior to version 0.24.2, there is a classical data racing issue about sub info list which could result in heap use after | Dec 27, 2025 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (41 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Emqx.
Media articles that mention a CVE ID that affects a product developed by Emqx — matched by CVE ID, not by vendor name.