CVE-2026-21888: MQTT v5 Variable Byte Integer parsing out-of-bounds: get_var_integer()
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. MQTT v5 Variable Byte Integer parsing out-of-bounds: getvarinteger() accepts 5-byte varints without bounds checks; reliably triggers OOB read / crash when built with ASan. This affects 0.24.6 and earlier.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21888?
CVE-2026-21888 is classified as a critical vulnerability due to the potential for out-of-bounds reads and crashes in the NanoMQ MQTT Broker.
How do I fix CVE-2026-21888?
To fix CVE-2026-21888, update NanoMQ to version 0.24.6 or later, where the vulnerable code has been patched.
What software is affected by CVE-2026-21888?
CVE-2026-21888 affects NanoMQ versions prior to 0.24.6.
What are the consequences of exploiting CVE-2026-21888?
Exploiting CVE-2026-21888 could lead to application crashes and potential data leaks due to out-of-bounds memory access.
What kind of systems are at risk due to CVE-2026-21888?
Systems running vulnerable versions of the NanoMQ MQTT Broker are at risk from CVE-2026-21888.