
I found a Heap Buffer Overflow in NanoMQ's URI parameter parsing logic. A classic off-by-one error during memory allocation leads to a null-byte overwrite via crafted HTTP requests. Tracked as CVE-2026-32135. Here is my original report: https://github.com/nanomq/nanomq/security/advisories/GHSA-6w96-9qw7-m599
Post summary
A heap buffer overflow (CVE‑2026‑32135) was disclosed in NanoMQ's URI parsing logic, caused by an off‑by‑one error leading to null‑byte overwrites via crafted HTTP requests.


