Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 30 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:emqx:nanomq:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Tue, 16 Dec 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Emqx
Emqx nanomq |
|
| Vendors & Products |
Emqx
Emqx nanomq |
Mon, 15 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Dec 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NanoMQ is a messaging broker/bus for IoT Edge & SDV. Versions prior to 0.24.4 have a buffer overflow case while the PUBLISH packets trigger both shared subscription and vanila subscription. This is fixed in version 0.24.4. As a workaround, disable shared subscription. | |
| Title | NanoMQ has Buffer Overflow | |
| Weaknesses | CWE-120 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-15T20:58:37.814Z
Reserved: 2025-09-23T14:33:49.506Z
Link: CVE-2025-59947
Updated: 2025-12-15T20:58:29.676Z
Status : Analyzed
Published: 2025-12-15T21:15:59.157
Modified: 2026-01-30T21:14:03.200
Link: CVE-2025-59947
No data.
OpenCVE Enrichment
Updated: 2025-12-16T20:45:31Z