CVE-2026-45151: Nanomq
Low severity, CVSS 2.9. EPSS: 0.3% chance of exploitation in the next 30 days.
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In 0.24.8 and earlier, quic_stream_recv can dereference a null substream pointer when a substream is in reopen state. The code finishes the AIO with error but does not return before locking c->mtx.
Affected products
- Nanomq Nanomq: up to and including 0.24.8
Published 2026-05-29. Last modified 2026-07-22.