Buffer overflow in NanoMQ - CVE-2025-59947
Published: April 24, 2026
NanoMQ
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service and modify data.
The vulnerability exists due to a buffer overflow in PUBLISH packet handling when triggering both shared subscription and vanilla subscription. A remote user can send a specially crafted PUBLISH packet to cause a denial of service and modify data.
User interaction is required.