Junglewise Threat Intelligence

CVE-2026-45151: NanoMQ MQTT Broker NULL pointer dereference in quic_stream_recv

CVE-2026-45151 · Severity: info · CVSS 2.9 · Published 2026-05-29

Vendors: NanoMQ.

Executive brief

NanoMQ is a messaging platform used to connect and manage data between Internet of Things (IoT) devices. A flaw in how the software handles specific network connections can cause the service to crash unexpectedly. This could allow an attacker to disrupt communications between devices, potentially leading to a loss of real-time data or service availability.

Technical details

A NULL pointer dereference exists in the `quic_stream_recv` function within `nng/src/supplemental/quic/msquic_dial.c`. When a QUIC substream is in a 'reopen' state, the code correctly identifies a NULL substream pointer and triggers an asynchronous I/O (AIO) error finish. However, it fails to return from the function after this error handling, proceeding to attempt a mutex lock (`nni_mtx_lock`) on the NULL pointer. An attacker can trigger this crash remotely by timing stream-state sequences, resulting in a process crash (Denial of Service).

Affected products

  • NanoMQ NanoMQ MQTT Broker <= 0.24.8

Timeline

  • 2026-05-12: advisory: GitHub Security Advisory published
  • 2026-05-29: disclosed: CVE published to NVD

References