CVE-2025-65953 Overview
CVE-2025-65953 is a heap Use-After-Free (UAF) vulnerability in NanoMQ MQTT Broker, an edge messaging platform. The flaw affects the TCP transport component that relies on the underlying NanoNNG library, specifically in src/sp/transport/mqtt/broker_tcp.c. The issue stems from improper resource management and premature cleanup of message and pipe structures when the broker processes malformed MQTT v5 retain message traffic. All versions prior to 0.22.5 are affected. The vulnerability is tracked under CWE-416: Use After Free.
Critical Impact
An authenticated network attacker can trigger memory corruption in the NanoMQ broker by sending crafted MQTT v5 retain messages, resulting in denial of service against the messaging platform.
Affected Products
- NanoMQ MQTT Broker versions prior to 0.22.5
- NanoNNG library component src/sp/transport/mqtt/broker_tcp.c
- Edge deployments relying on NanoMQ TCP transport for MQTT v5 traffic
Discovery Timeline
- 2025-11-25 - CVE-2025-65953 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-65953
Vulnerability Analysis
The vulnerability resides in the TCP transport layer of NanoMQ, which handles MQTT client sessions over standard TCP sockets. When the broker processes specific malformed MQTT v5 retain messages, the message and pipe structures backing the connection are freed prematurely. Subsequent code paths continue to reference the freed heap memory, producing a Use-After-Free condition. Exploitation requires network reachability to the broker and the ability to authenticate at a low privilege level to submit MQTT PUBLISH traffic with the retain flag set.
Root Cause
The root cause is improper lifecycle management of nng_msg and pipe objects inside broker_tcp.c. Under normal traffic, the broker owns these structures for the duration of message dispatch. Malformed MQTT v5 retain packets desynchronize the release path, causing the broker to release the object while another code path retains a dangling pointer. Accessing that pointer produces heap corruption within the broker process.
Attack Vector
An attacker connects to the NanoMQ broker over TCP, authenticates with valid low-privilege credentials, and publishes a crafted MQTT v5 message with the retain flag and malformed properties. The broker parses the message, frees internal structures, and then dereferences them during retain processing. The result is broker instability and denial of service for all connected MQTT clients. The advisory does not describe remote code execution, and the CVSS vector reflects an availability-only impact.
No public proof-of-concept exploit code is available. Refer to the GitHub Security Advisory GHSA-r95p-wjm8-2qxr for coordinated disclosure details.
Detection Methods for CVE-2025-65953
Indicators of Compromise
- Unexpected crashes, restarts, or segmentation faults of the nanomq broker process
- Abnormal volume of MQTT v5 PUBLISH messages with the retain flag set from a single authenticated client
- MQTT client disconnects across all sessions coinciding with broker termination
- Core dumps containing heap corruption signatures inside functions declared in broker_tcp.c
Detection Strategies
- Monitor the NanoMQ broker version banner and inventory hosts still running versions below 0.22.5
- Enable verbose broker logging and alert on parser errors tied to MQTT v5 property decoding on retain messages
- Correlate broker process exits with recent client PUBLISH activity to isolate the source client identity
- Deploy MQTT-aware network sensors that flag protocol violations in v5 property fields
Monitoring Recommendations
- Track uptime and restart counts for the NanoMQ service using host telemetry
- Capture and retain MQTT broker logs in a centralized log store for retrospective analysis
- Alert when the same client identifier repeatedly triggers broker parser errors within a short window
How to Mitigate CVE-2025-65953
Immediate Actions Required
- Upgrade NanoMQ to version 0.22.5 or later on all broker hosts
- Audit MQTT credentials and revoke any low-privilege accounts that are no longer required
- Restrict network access to the broker's TCP listener using firewall rules or a private network segment
- Enable process supervision so the broker restarts automatically after a crash while patching proceeds
Patch Information
The maintainers fixed the Use-After-Free in NanoMQ version 0.22.5. The patch corrects the lifecycle of message and pipe structures in src/sp/transport/mqtt/broker_tcp.c so retain message processing no longer references freed memory. Full release details are available in the NanoMQ Security Advisory GHSA-r95p-wjm8-2qxr.
Workarounds
- Disable MQTT v5 retain message handling if the broker deployment does not require it
- Place the broker behind an MQTT-aware proxy that validates v5 property fields before forwarding
- Limit which authenticated clients are permitted to publish messages with the retain flag using ACLs
# Example: restrict retain publishing via NanoMQ ACL configuration
rules = [
{
action = "publish"
topics = ["#"]
retain = false
username = "untrusted_client"
permit = "deny"
}
]
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
