Vulnerability Description
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In 0.24.8 and earlier, quic_stream_recv can dereference a null substream pointer when a substream is in reopen state. The code finishes the AIO with error but does not return before locking c->mtx.
Related Weaknesses (CWE)
References
- https://github.com/nanomq/nanomq/security/advisories/GHSA-9qhf-wgp4-p7w5
- https://github.com/nanomq/nanomq/security/advisories/GHSA-9qhf-wgp4-p7w5
FAQ
What is CVE-2026-45151?
CVE-2026-45151 is a documented vulnerability. NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In 0.24.8 and earlier, quic_stream_recv can dereference a null substream pointer when a substream is in reopen state. The code fin...
How severe is CVE-2026-45151?
CVSS scoring is not yet available for CVE-2026-45151. Check NVD for updates.
Is there a patch for CVE-2026-45151?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.