NanoMQ v0.17.9 was discovered to contain a heap use-after-free vulnerability via the component sub_Ctx_handle. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SUBSCRIBE message.
Metrics
Affected Vendors & Products
References
History
Wed, 06 Aug 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:emqx:nanomq:0.17.9:*:*:*:*:*:*:* |
Wed, 30 Jul 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Emqx
Emqx nanomq |
|
Vendors & Products |
Emqx
Emqx nanomq |
Tue, 29 Jul 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-400 | |
Metrics |
cvssV3_1
|
Tue, 29 Jul 2025 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | NanoMQ v0.17.9 was discovered to contain a heap use-after-free vulnerability via the component sub_Ctx_handle. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SUBSCRIBE message. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-07-29T00:00:00.000Z
Updated: 2025-07-29T18:37:09.983Z
Reserved: 2024-08-05T00:00:00.000Z
Link: CVE-2024-42651

Updated: 2025-07-29T18:37:05.274Z

Status : Analyzed
Published: 2025-07-29T19:15:43.180
Modified: 2025-08-06T16:40:47.270
Link: CVE-2024-42651

No data.