CVE-2024-42649: Medium severity nanomq nanomq vulnerability
Published Jul 14, 2025
·Updated
NanoMQ v0.22.10 was discovered to contain a memory leak which allows attackers to cause a Denial of Service (DoS) via a crafted PUBLISH message.
Affected Software
2 affected components
nanomq nanomq
emqx Nanomq=0.22.10
Event History
Jul 14, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-42649?
CVE-2024-42649 has a high severity rating due to its potential to cause a Denial of Service (DoS) through a memory leak.
2
How do I fix CVE-2024-42649?
To fix CVE-2024-42649, update NanoMQ to a version higher than 0.22.10 that addresses the memory leak issue.
3
What impact does CVE-2024-42649 have on my system?
CVE-2024-42649 can lead to a Denial of Service, causing the application to become unresponsive or crash when a crafted PUBLISH message is received.
4
Is CVE-2024-42649 specific to certain versions of NanoMQ?
Yes, CVE-2024-42649 specifically affects NanoMQ version 0.22.10.
5
Who is affected by CVE-2024-42649?
Any organization or individual using NanoMQ version 0.22.10 is vulnerable to CVE-2024-42649.