Type Confusion in NanoMQ - CVE-2026-44640
Published: May 23, 2026
NanoMQ
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to type confusion in nng/src/supplemental/quic/msquic_dial.c when closing a QUIC dialer with a pending dial AIO. A remote attacker can trigger the dialer close path to cause a denial of service.
User interaction is required to initiate the vulnerable local code path.