CVE-2025-59946: NanoMQ has a Use After Free vulnerability via sub info list
Published Dec 27, 2025
·Updated
NanoMQ MQTT Broker (NanoMQ) is an Edge Messaging Platform. Prior to version 0.24.2, there is a classical data racing issue about sub info list which could result in heap use after free crash. This issue has been patched in version 0.24.2.
Affected Software
2 affected components
nanomq nanomq<0.24.2
emqx Nanomq<0.24.4
Event History
Dec 27, 2025
CVE Published
via MITRE·12:40 AM
Data Sourced
via MITRE·12:40 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-59946?
CVE-2025-59946 has been classified as a critical vulnerability due to the potential for heap use after free crashes.
2
How do I fix CVE-2025-59946?
To fix CVE-2025-59946, upgrade NanoMQ to version 0.24.2 or later where the issue has been patched.
3
What impact does CVE-2025-59946 have on NanoMQ?
CVE-2025-59946 can lead to unstable behavior and crashes within the NanoMQ broker due to a data racing issue.
4
Is CVE-2025-59946 present in all versions of NanoMQ?
CVE-2025-59946 affects all versions of NanoMQ prior to 0.24.2.
5
How can I identify if my system is vulnerable to CVE-2025-59946?
If you are running a version of NanoMQ less than 0.24.2, your system is vulnerable to CVE-2025-59946.