CVE-2026-32135Disclosure(emqx / nanomq)

LOWCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for emqx nanomq systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.11 have a remotely triggerable heap buffer overflow in the `uri_param_parse` function of NanoMQ's REST API. The vulnerability occurs due to an off-by-one error when allocating memory for query parameter keys and values, allowing an attacker to write a null byte beyond the allocated buffer. This can be triggered via a crafted HTTP request. Version 0.24.11 patches the issue.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nanomq

Threat summary

  • Active exploitation appears in 1 classified signals
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-20); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
nanomq

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-20: 1Mentions · 2026-04-21: 1Mentions · 2026-05-02: 1Active Exploitation · 2026-04-20: 1Technical Details · 2026-04-21: 1Technical Details · 2026-05-02: 104-2004-2105-02
Signal classification2 categories
Disclosure
266.7%
Active Exploitation
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-201
Active Exploitation1
2026-04-211
Disclosure1
2026-05-021
Disclosure1
Full discourse3 posts
  • Fatih Çelik@fatihclk01
    Disclosure

    I found a Heap Buffer Overflow in NanoMQ's URI parameter parsing logic. A classic off-by-one error during memory allocation leads to a null-byte overwrite via crafted HTTP requests. Tracked as CVE-2026-32135. Here is my original report: https://github.com/nanomq/nanomq/security/advisories/GHSA-6w96-9qw7-m599

    Post summary

    A heap buffer overflow (CVE‑2026‑32135) was disclosed in NanoMQ's URI parsing logic, caused by an off‑by‑one error leading to null‑byte overwrites via crafted HTTP requests.

    10062297
    474 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    A lot of offensive activities were identified targeting NanoMQ MQTT Broker (CVE-2026-32135) https://vuldb.com/vuln/358356/cti

    Post summary

    The message reports widespread active exploitation of CVE-2026-32135 against NanoMQ MQTT Broker, without providing PoC, exploit code, or mitigation information.

    0101074
    2.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32135 NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.11 have a remotely triggerable heap buffer overflow in the `uri_param_par… https://www.cve.org/CVERecord?id=CVE-2026-32135

    Post summary

    The entry reports a remotely triggerable heap buffer overflow in NanoMQ MQTT Broker (affected before v0.24.11), referencing the CVE record, with no indication of PoC, exploit code, active exploitation, or available fix.

    0000096
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appemqxnanomq---

Explore more