CVE-2026-22040

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In version 0.24.6, by generating a combined traffic pattern of high-frequency publishes and rapid reconnect/kick-out using the same ClientID and massive subscribe/unsubscribe jitter, it is possible to reliably trigger heap memory corruption in the Broker process, causing it to exit immediately with SIGABRT due to free(): invalid pointer. As of time of publication, no known patched versions are available.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:emqx:nanomq:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-04 22:16

Updated : 2026-03-18 16:09


NVD link : CVE-2026-22040

Mitre link : CVE-2026-22040

CVE.ORG link : CVE-2026-22040


JSON object : View

Products Affected

emqx

  • nanomq
CWE
CWE-416

Use After Free