CVE-2026-44639: Nanomq

Low severity, CVSS 3.7. EPSS: 0.4% chance of exploitation in the next 30 days.

NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's MQTT v5 property decoder in nng/src/supplemental/mqtt/mqtt_codec.c uses property_append() to walk the entire linked list for each property added by decode_buf_properties(). A remote unauthenticated client can supply a PUBLISH or SUBSCRIBE packet containing many User Properties, causing O(N²) linked-list insertion and CPU work that makes the broker unresponsive; repeated packets can sustain the denial of service. This issue is fixed in version 0.24.14.

Affected products

  • Nanomq Nanomq: before 0.24.14 (fixed in 0.24.14)

Published 2026-09-18. Last modified 2026-09-18.