CVE-2025-65953

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.22.5, a Heap-Use-After-Free (UAF) vulnerability exists in the TCP transport component of NanoMQ, which relies on the underlying NanoNNG library (specifically in src/sp/transport/mqtt/broker_tcp.c). The vulnerability is due to improper resource management and premature cleanup of message and pipe structures under specific malformed MQTTV5 retain message traffic conditions. This issue has been patched in version 0.22.5.
CVSS

No CVSS.

Configurations

No configuration.

History

25 Nov 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-25 23:15

Updated : 2025-12-01 15:39


NVD link : CVE-2025-65953

Mitre link : CVE-2025-65953

CVE.ORG link : CVE-2025-65953


JSON object : View

Products Affected

No product.

CWE
CWE-416

Use After Free