CVE 8.5 HIGH

NanoMQ has Buffer Overflow_CVE-2025-59947

8.5 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H

Description

NanoMQ is a messaging broker/bus for IoT Edge & SDV. Versions prior to 0.24.4 have a buffer overflow case while the PUBLISH packets trigger both shared subscription and vanila subscription. This is fixed in version 0.24.4. As a workaround, disable shared subscription.

AI Analysis

Buffer overflow in NanoMQ messaging broker/bus for IoT Edge & SDV

Basic Information

ID CVE-2025-59947
Source GitHub_M
Published Dec 15, 2025 at 20:19
Modified Dec 15, 2025 at 20:58

Affected Product

Vendor nanomq
Product nanomq
Version < 0.24.4
Affected Versions nanomq nanomq < 0.24.4

CWE Classification

AI Assessment

AI Score 8.5 / 10
AI Severity High
Vendor NanoMQ
Product NanoMQ
Version < 0.24.4

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.