CVE-2024-42648: Medium severity nanomq nanomq vulnerability
Published Jul 14, 2025
·Updated
NanoMQ v0.22.10 was discovered to contain a heap overflow which allows attackers to cause a Denial of Service (DoS) via a crafted CONNECT message.
Affected Software
2 affected components
nanomq nanomq
emqx Nanomq=0.22.10
Event History
Jul 14, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-42648?
CVE-2024-42648 is classified as a high severity vulnerability due to its potential for causing Denial of Service (DoS) through a heap overflow.
2
How do I fix CVE-2024-42648?
To fix CVE-2024-42648, update NanoMQ to version 0.22.11 or later that addresses this heap overflow vulnerability.
3
What version of NanoMQ is affected by CVE-2024-42648?
CVE-2024-42648 affects NanoMQ version 0.22.10.
4
What type of exploitation is possible with CVE-2024-42648?
CVE-2024-42648 allows attackers to exploit the vulnerability by sending a crafted CONNECT message leading to Denial of Service.
5
Is there a workaround for CVE-2024-42648?
There are no specific workarounds for CVE-2024-42648; the best course of action is to apply the software update.