CVE-2023-34488: Emqx Nanomq

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

NanoMQ 0.17.5 has a one-byte heap-based buffer over-read in the conn_handler function of mqtt_parser.c when it processes malformed messages.

Affected products

  • Emqx Nanomq: version 0.17.5 only

Published 2023-06-12. Last modified 2026-06-17.