CVE-2025-59947: Emqx Nanomq
Critical severity, CVSS 9.0. EPSS: 0.3% chance of exploitation in the next 30 days.
NanoMQ is a messaging broker/bus for IoT Edge & SDV. Versions prior to 0.24.4 have a buffer overflow case while the PUBLISH packets trigger both shared subscription and vanila subscription. This is fixed in version 0.24.4. As a workaround, disable shared subscription.
Affected products
- Emqx Nanomq: before 0.24.4 (fixed in 0.24.4)
Published 2025-12-15. Last modified 2026-06-17.