{"id":"CVE-2026-34608","summary":"nanomq: Heap-Buffer-Overflow in webhook_inproc.c via cJSON_Parse OOB Read","details":"NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.10, in NanoMQ's webhook_inproc.c, the hook_work_cb() function processes nng messages by parsing the message body with cJSON_Parse(body). The body is obtained from nng_msg_body(msg), which is a binary buffer without a guaranteed null terminator. This leads to an out-of-bounds read (OOB read) as cJSON_Parse reads until it finds a \\0, potentially accessing memory beyond the allocated buffer (e.g., nng_msg metadata or adjacent heap/stack). The issue is often masked by nng's allocation padding (extra 32 bytes of zeros for non-power-of-two sizes \u003c1024 or non-aligned). The overflow is reliably triggered when the JSON payload length is a power-of-two \u003e=1024 (no padding added). This issue has been patched in version 0.24.10.","aliases":["GHSA-8p57-jxj9-3qq3"],"modified":"2026-08-12T16:25:03.920763Z","published":"2026-04-02T17:52:51.813Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-125","CWE-457"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/34xxx/CVE-2026-34608.json"},"references":[{"type":"WEB","url":"https://github.com/nanomq/nanomq/releases/tag/0.24.10"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/34xxx/CVE-2026-34608.json"},{"type":"ADVISORY","url":"https://github.com/nanomq/nanomq/security/advisories/GHSA-8p57-jxj9-3qq3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34608"},{"type":"FIX","url":"https://github.com/nanomq/nanomq/commit/9499a4b2c47998a6aadb69238c18b9e6771b1691"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nanomq/nanomq","events":[{"introduced":"0"},{"fixed":"24e6327aa79d57c5d92e2119a94396a8fc213051"},{"fixed":"9499a4b2c47998a6aadb69238c18b9e6771b1691"}],"database_specific":{"cpe":"cpe:2.3:a:emqx:nanomq:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.24.10"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["0.24.9","0.24.8","0.24.7","0.24.6","0.24.5","0.24.4","0.24.3-5","0.24.3","0.24.2","0.24.1","0.24.0","0.23.10","0.23.9","0.23.8","0.23.7-11","0.23.7","0.23.6","0.23.5","0.23.4","0.23.3","0.23.2","0.23.1","0.23.0","0.22.10","0.22.8","0.22.7","0.22.6","0.22.2","0.22.3","0.22.1","0.22.0","0.21.10","0.21.9","0.21.8","0.21.7","0.21.6","0.21.5","0.21.2","0.21.1","0.21","0.20.8","0.20.6","0.20.5","0.20.0","0.19.5","0.19.1","0.19.0","0.18.2","0.18.1","0.17.8","0.17.5","0.17.2","0.16.5","0.16.3","0.16.2","0.16.0","0.15.5","0.15.3","0.15.2","0.15.1","0.15.0","0.14.8","0.14.5","0.12.1","0.14.1","0.14.0","0.13.8","0.13.6","0.13.0","0.12.5","0.12.2","0.12.0","0.11.82","0.11.8","0.11.5","0.11.3","0.11.2","0.11.0","0.10.8","0.10.5","0.10.1","0.9.7","0.9.5","0.9.2","0.9.0","0.8.6log","0.8.5","0.8.3","0.8.0","0.7.9","0.7.8","0.7.5","0.7.5rc","0.7.4rc","0.7.4","0.7.3","0.7.2","0.6.8","0.7.0","0.6.7rc","0.6.4","0.6.3","0.6.2","0.6.0","0.5.9","0.5.8","0.5.5","0.5.2","0.5.0","0.4.8","0.4.5","0.4.3","0.4.2","0.4.1","0.4.0","0.3.8","0.3.5","0.3.4","0.3.3","0.3.2","0.3.0","0.2.5","0.2.2","0.2.1","0.2.0","0.1.0","0.0.3","0.0.2","0.0.1"],"database_specific":{"vanir_signatures":[{"id":"CVE-2026-34608-9788705e","signature_type":"Line","signature_version":"v1","source":"https://github.com/nanomq/nanomq/commit/9499a4b2c47998a6aadb69238c18b9e6771b1691","target":{"file":"nanomq/webhook_inproc.c"},"deprecated":false,"digest":{"line_hashes":["121843657267935642656130158138176891788","287213901573589411200829291389447440699","99945957393350894679175477653207946240","48624586610002043879352321955294462592","217265588641447269070578241624205556102","102543071575554571766746900534897394883","26761939698220736799609110349041741755","203286401508593385023227462900732517715","176366741767967063616672497623217093647","316218832441502259928426788195979547038","307688872524718107954906043705062557311","63780027845780909962654273186901381994","135448864733645365584837172160280405947","303066027830019687690824301904546797537","194852154050258948756978817596862109562","60733929636672201446808192535433501532","146984447729060297647349122882280829216","150153022814860940863602979703116845824","81526078173626017252478404313111489662","143500124616812177856697113215209200052","278603067511924560569027235819740622750","138915991543129542030724830256933852415","213025847090433122091314458125453541514","264456041354531249476250506138252113139","337903250148432640848115211707103276181","20727219043272191113573430764100197519"],"threshold":0.9}},{"target":{"file":"nanomq/webhook_inproc.c","function":"hook_work_cb"},"deprecated":false,"digest":{"function_hash":"282239524165529053366892576943462394676","length":5962},"id":"CVE-2026-34608-d6d8ff79","signature_type":"Function","signature_version":"v1","source":"https://github.com/nanomq/nanomq/commit/9499a4b2c47998a6aadb69238c18b9e6771b1691"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-34608.json","vanir_signatures_modified":"2026-08-12T16:25:03Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"}]}