CVE-2025-59946 Details
Description
NanoMQ MQTT Broker (NanoMQ) is an Edge Messaging Platform. Prior to version 0.24.2, there is a classical data racing issue about sub info list which could result in heap use after free crash. This issue has been patched in version 0.24.2.
A use-after-free vulnerability has been identified in NanoMQ MQTT Broker versions prior to 0.24.2. This issue arises from a data race condition related to the subscription information list, which can lead to a heap-based use-after-free crash. The vulnerability can be exploited by sending crafted MQTT messages that manipulate the subscription process, causing the broker to crash.
Users can upgrade to NanoMQ version 0.24.4 or later, where this vulnerability has been fixed. In the meantime, it is recommended to limit the rate of subscription and unsubscription requests, as high concurrency can trigger the issue.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 29, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/nanomq/nanomq/issues/1863 | [email protected] | ExploitIssue Tracking |
| https://github.com/nanomq/nanomq/security/advisories/GHSA-xg37-23w7-72p5 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| emqx nanomq | < 0.24.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 30, 2026 | Initial Analysis | [email protected] |
| Dec 27, 2025 | New CVE Received | [email protected] |