CVE-2025-59947: NanoMQ has Buffer Overflow
Published Dec 15, 2025
·Updated
NanoMQ is a messaging broker/bus for IoT Edge & SDV. Versions prior to 0.24.4 have a buffer overflow case while the PUBLISH packets trigger both shared subscription and vanila subscription. This is fixed in version 0.24.4. As a workaround, disable shared subscription.
Affected Software
2 affected components
NanoMQ<0.24.4
emqx Nanomq<0.24.4
Remediation
Patch Available
Event History
Dec 15, 2025
CVE Published
via MITRE·08:19 PM
Data Sourced
via MITRE·08:19 PM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-59947?
CVE-2025-59947 is classified as a high-severity vulnerability due to the buffer overflow that can be triggered by PUBLISH packets.
2
How do I fix CVE-2025-59947?
To fix CVE-2025-59947, update to NanoMQ version 0.24.4 or later.
3
What versions of NanoMQ are affected by CVE-2025-59947?
CVE-2025-59947 affects all versions of NanoMQ prior to 0.24.4.
4
Is there a workaround for CVE-2025-59947?
Yes, a workaround for CVE-2025-59947 is to disable shared subscriptions in the affected versions.
5
What type of issue is CVE-2025-59947?
CVE-2025-59947 is a buffer overflow vulnerability affecting how PUBLISH packets are handled in NanoMQ.