{"id":"CVE-2026-22040","summary":"NanoMQ 0.24.6 Use-After-Free Leading to Heap Corruption and Broker Crash","details":"NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In version 0.24.6, by generating a combined traffic pattern of high-frequency publishes and rapid reconnect/kick-out using the same ClientID and massive subscribe/unsubscribe jitter, it is possible to reliably trigger heap memory corruption in the Broker process, causing it to exit immediately with SIGABRT due to free(): invalid pointer. As of time of publication, no known patched versions are available.","aliases":["GHSA-v57q-w88m-424r"],"modified":"2026-08-12T03:51:26.749419572Z","published":"2026-03-04T21:55:11.238Z","database_specific":{"cwe_ids":["CWE-416"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22040.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22040.json"},{"type":"ADVISORY","url":"https://github.com/nanomq/nanomq/security/advisories/GHSA-v57q-w88m-424r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22040"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nanomq/nanomq","events":[{"introduced":"dc3a3136cd82d5c005b8cd26a65fe53beaaf0eb9"},{"fixed":"dc3a3136cd82d5c005b8cd26a65fe53beaaf0eb9"}],"database_specific":{"extracted_events":[{"introduced":"= 0.24.6"},{"last_affected":"= 0.24.6"},{"introduced":"0"},{"fixed":"0.24.6"}],"source":["AFFECTED_FIELD","CPE_RANGE"],"cpe":"cpe:2.3:a:emqx:nanomq:*:*:*:*:*:*:*:*"}}],"versions":["= 0.24.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22040.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}