CVE-2026-35217 Details
Description
NanoMQ contains a protocol-semantics flaw in its MQTT v5 `SUBSCRIBE` handling: if a subscription entry is missing the final 1-byte `Subscription Options` field, the broker may still accept the malformed packet and install the subscription into internal broker state. Under a specific packet-length construction, the same parser flaw also causes a 1-byte out-of-bounds read that crosses the real heap allocation boundary and is detected by ASAN as a `heap-buffer-overflow`. If the consumed byte happens to look acceptable, NanoMQ may continue and append the malformed subscription entry into its internal `subinfol` state. In that case, a `SUBSCRIBE` packet that should be rejected by MQTT rules is instead treated as a successful subscription. Whether ASAN reports the bug does not depend on MQTT's logical `remain` boundary; it depends on whether the read crosses the real heap allocation boundary of the underlying message buffer. In other words, these are not two unrelated issues. They are two manifestations of the same parsing defect: by default, it appears as a semantic vulnerability, and under suitable input conditions, it also becomes a verifiable out-of-bounds read vulnerability.
A protocol-semantics vulnerability has been identified in NanoMQ's MQTT v5 SUBSCRIBE handling, specifically in versions through 0.24.x. The issue arises when a subscription entry omits the final 1-byte Subscription Options field. In such cases, the broker may still accept the malformed packet and incorporate the subscription into its internal state. This flaw can be exploited to create a 1-byte out-of-bounds read that crosses the actual heap allocation boundary, resulting in a heap-buffer-overflow error detected by AddressSanitizer (ASAN). The vulnerability manifests as a semantic acceptance of malformed SUBSCRIBE packets, which should have been rejected according to MQTT rules, and under certain conditions, it leads to a verifiable memory-safety violation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 20, 2026CISA-ADP
Assessed Jul 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/nanomq/nanomq/security/advisories/GHSA-w4xh-p384-w556 | CISA-ADP | AdvisoryExploitTechnical AnalysisVendor |
| https://github.com/nanomq/nanomq/security/advisories/GHSA-w4xh-p384-w556 | [email protected] | AdvisoryExploitTechnical AnalysisVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| NanoMQ | <= 0.24.x |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 20, 2026 | CVE Modified | CISA-ADP |
| Jul 20, 2026 | New CVE Received | [email protected] |
Volerion