CVE-2026-45151

Severity CVSS v4.0:
LOW
Type:
CWE-476 NULL Pointer Dereference
Publication date:
29/05/2026
Last modified:
29/05/2026

Description

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In 0.24.8 and earlier, quic_stream_recv can dereference a null substream pointer when a substream is in reopen state. The code finishes the AIO with error but does not return before locking c->mtx.