CVE-2025-59946: Emqx Nanomq

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

NanoMQ MQTT Broker (NanoMQ) is an Edge Messaging Platform. Prior to version 0.24.2, there is a classical data racing issue about sub info list which could result in heap use after free crash. This issue has been patched in version 0.24.2.

Affected products

  • Emqx Nanomq: before 0.24.4 (fixed in 0.24.4)

Published 2025-12-27. Last modified 2026-06-17.