CVE-2026-32134
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In versions 0.24.10 and below, when NanoMQ handles high-concurrency reconnect traffic using a reconnect-collision payload, the broker can crash due to a NULL pointer dereference during MQTT session resumption for clean_start=0 clients. The transport's p_peer callback (tcptran_pipe_peer()) iterates cpipe->subinfol while copying session metadata from the cached old pipe to the new reconnecting pipe, without checking whether the pointer is NULL. Under a reconnect race, cpipe->subinfol can be freed and set to NULL before session restore invokes this function, resulting in a remote unauthenticated Denial-of-Service (process crash) condition. This issue has been fixed in version 0.24.11.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 5.9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.53%
- Percentil entre todas las CVEs puntuadas: 43
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-476
Referencias
- https://github.com/nanomq/NanoNNG/commit/522ec62e29e60d1122f2aedaa6e702dcf089f7bb
- https://github.com/nanomq/nanomq/issues/2241
- https://github.com/nanomq/nanomq/releases/tag/0.24.11
- https://github.com/nanomq/nanomq/security/advisories/GHSA-q36f-83mh-pcv2
- https://github.com/nanomq/nanomq/issues/2241
- https://github.com/nanomq/nanomq/security/advisories/GHSA-q36f-83mh-pcv2
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-32134",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-32134",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-05-19T17:58:24.262200Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.9,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "nanomq",
"product": "nanomq",
"versions": [
{
"status": "affected",
"version": "< 0.24.11"
}
]
},
{
"vendor": "nanomq",
"product": "NanoNNG",
"versions": [
{
"status": "affected",
"version": "< 0.24.11"
}
]
}
]
}
],
"published": "2026-05-19T18:16:21.147",
"references": [
{
"url": "https://github.com/nanomq/NanoNNG/commit/522ec62e29e60d1122f2aedaa6e702dcf089f7bb",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/nanomq/nanomq/issues/2241",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/nanomq/nanomq/releases/tag/0.24.11",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/nanomq/nanomq/security/advisories/GHSA-q36f-83mh-pcv2",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/nanomq/nanomq/issues/2241",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
},
{
"url": "https://github.com/nanomq/nanomq/security/advisories/GHSA-q36f-83mh-pcv2",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-476"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In versions 0.24.10 and below, when NanoMQ handles high-concurrency reconnect traffic using a reconnect-collision payload, the broker can crash due to a NULL pointer dereference during MQTT session resumption for clean_start=0 clients. The transport's p_peer callback (tcptran_pipe_peer()) iterates cpipe->subinfol while copying session metadata from the cached old pipe to the new reconnecting pipe, without checking whether the pointer is NULL. Under a reconnect race, cpipe->subinfol can be freed and set to NULL before session restore invokes this function, resulting in a remote unauthenticated Denial-of-Service (process crash) condition. This issue has been fixed in version 0.24.11."
},
{
"lang": "es",
"value": "NanoMQ MQTT Broker (NanoMQ) es una plataforma de mensajería de borde integral. En las versiones 0.24.10 e inferiores, cuando NanoMQ maneja tráfico de reconexión de alta concurrencia utilizando una carga útil de colisión de reconexión, el broker puede fallar debido a una desreferenciación de puntero NULL durante la reanudación de la sesión MQTT para clientes con clean_start=0. La devolución de llamada p_peer del transporte (tcptran_pipe_peer()) itera cpipe -> subinfol mientras copia metadatos de sesión desde la tubería antigua en caché a la nueva tubería de reconexión, sin verificar si el puntero es NULL. Bajo una condición de carrera de reconexión, cpipe -> subinfol puede ser liberado y establecido en NULL antes de que la restauración de la sesión invoque esta función, resultando en una condición de Denegación de Servicio remota no autenticada (fallo del proceso). Este problema ha sido solucionado en la versión 0.24.11."
}
],
"lastModified": "2026-07-24T12:10:00.210",
"sourceIdentifier": "security-advisories@github.com"
}