Executive brief
NanoMQ is a lightweight messaging engine used for communication between IoT devices. A vulnerability in how it handles certain messages allows a malicious server to crash the NanoMQ client or bridge. This can lead to a permanent loss of connectivity if the system enters a continuous crash-and-restart loop, disrupting data flow from IoT sensors or devices.
Technical details
A NULL pointer dereference exists in the `nni_mqttv5_msg_decode_connect()` function within `mqtt_codec.c`. The vulnerability is triggered when the decoder incorrectly uses the `prop` variable instead of `will_prop` while iterating over MQTTv5 CONNECT properties. If a packet contains 'will' properties but no connect-level properties, the code attempts to dereference a NULL pointer, leading to a SIGSEGV crash. This affects both the `nanomq_cli` and the core bridge mode. An attacker controlling a malicious broker can trigger this with a single 35-byte packet, potentially causing a persistent DoS via infinite crash loops during auto-reconnection.
Affected products
- nanomq nanomq <= 0.24.11
Timeline
- 2026-06-26: disclosed: Advisory published on GitHub
- 2026-07-20: advisory: CVE published to NVD