CVE-2024-42651
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-07-29

Last updated on: 2025-08-06

Assigner: MITRE

Description
NanoMQ v0.17.9 was discovered to contain a heap use-after-free vulnerability via the component sub_Ctx_handle. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SUBSCRIBE message.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-07-29
Last Modified
2025-08-06
Generated
2026-05-07
AI Q&A
2025-07-29
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
emqx nanomq 0.17.9
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is a heap use-after-free (UAF) issue in NanoMQ version 0.17.9, specifically in the component sub_Ctx_handle. It occurs due to improper management of retained messages, which leads to accessing memory that has already been freed. This flaw can be triggered by a crafted SUBSCRIBE message. [1]


How can this vulnerability impact me? :

An attacker can exploit this vulnerability to cause a Denial of Service (DoS) condition in NanoMQ by sending a specially crafted SUBSCRIBE message, potentially crashing the service or disrupting its normal operation. [1]


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart