CVE-2026-44640: NanoMQ: QUIC Dialer Close Type Confusion
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to 0.24.14, aio->provdata is stored as nniquicconn during dialing, but read as exquicconn during dialer close. This type confusion causes invalid object interpretation and leads to close-path hang/crash behavior. This vulnerability is fixed in 0.24.14.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NanoMQ MQTT Broker (NanoMQ)to a version that resolves this vulnerability.Fixed in 0.24.14
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44640?
The severity of CVE-2026-44640 is medium with a score of 4.5.
How do I fix CVE-2026-44640?
To fix CVE-2026-44640, upgrade NanoMQ to version 0.24.14 or later.
What does CVE-2026-44640 affect?
CVE-2026-44640 affects the NanoMQ MQTT Broker prior to version 0.24.14.
What is the impact of CVE-2026-44640?
CVE-2026-44640 may lead to close-path hang or crash behavior due to type confusion.
Is CVE-2026-44640 a high-risk vulnerability?
CVE-2026-44640 is categorized as a medium-risk vulnerability, with a risk score of 34.