CVE-2025-59947

Severity CVSS v4.0:
HIGH
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
15/12/2025
Last modified:
30/01/2026

Description

NanoMQ is a messaging broker/bus for IoT Edge & SDV. Versions prior to 0.24.4 have a buffer overflow case while the PUBLISH packets trigger both shared subscription and vanila subscription. This is fixed in version 0.24.4. As a workaround, disable shared subscription.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:emqx:nanomq:*:*:*:*:*:*:*:* 0.24.4 (excluding)