CVE-2026-44639
3.7 LOWpublic exploit availablePublished 2026-09-18 · Updated 2026-09-18
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's MQTT v5 property decoder in nng/src/supplemental/mqtt/mqtt_codec.c uses property_append() to walk the entire linked list for each property added by decode_buf_properties(). A remote unauthenticated client can supply a PUBLISH or SUBSCRIBE packet containing many User Properties, causing O(N²) linked-list insertion and CPU work that makes the broker unresponsive; repeated packets can sustain the denial of service. This issue is fixed in version 0.24.14.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Weaknesses
CWE-407
Public exploit & PoC references
- https://github.com/nanomq/NanoNNG/commit/91bd4c7f45f945a3f5f0e37c459157dc7c277a07
- https://github.com/nanomq/NanoNNG/pull/1508
- https://github.com/nanomq/nanomq/releases/tag/0.24.14
- https://github.com/nanomq/nanomq/security/advisories/GHSA-6mwg-445v-2qrv
- https://github.com/nanomq/nanomq/security/advisories/GHSA-6mwg-445v-2qrv
All references
- https://github.com/nanomq/NanoNNG/commit/91bd4c7f45f945a3f5f0e37c459157dc7c277a07
- https://github.com/nanomq/NanoNNG/pull/1508
- https://github.com/nanomq/nanomq/releases/tag/0.24.14
- https://github.com/nanomq/nanomq/security/advisories/GHSA-6mwg-445v-2qrv
- https://github.com/nanomq/nanomq/security/advisories/GHSA-6mwg-445v-2qrv
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-100700PoC
- MEDIUMCVE-2026-102277PoC
- MEDIUMCVE-2026-19668
- UNSCOREDCVE-2026-42772PoC
- HIGHCVE-2026-61814PoC
- HIGHCVE-2026-63446PoC
- HIGHCVE-2026-63447PoC
- MEDIUMCVE-2026-63448PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.