CVE-2026-61633 Overview
CVE-2026-61633 affects NanoMQ, a lightweight Message Queuing Telemetry Transport (MQTT) broker. The vulnerability resides in the nni_mqtt_msg_decode_unsubscribe() function within nng/src/supplemental/mqtt/mqtt_codec.c. The function fails to handle a failed read_uint16() call while counting topics inside a malformed UNSUBSCRIBE packet. A malicious MQTT broker can send a zero-length topic followed by trailing data, leaving buf.curpos unchanged while topic_count continues to increase. This condition hangs the connecting MQTT 3.1.1 client, consumes CPU and memory, and repeatedly denies service when automatic reconnection is enabled. Versions prior to 0.24.14 are affected. The broker-side nmq_unsubinfo_decode path is not impacted.
Critical Impact
A malicious broker can trigger an infinite loop in connecting NanoMQ clients, causing sustained CPU and memory exhaustion and repeated denial of service across reconnect cycles.
Affected Products
- NanoMQ MQTT broker client versions prior to 0.24.14
- MQTT 3.1.1 clients using nni_mqtt_msg_decode_unsubscribe() in NanoNNG
- Applications embedding the vulnerable mqtt_codec.c parser
Discovery Timeline
- 2026-09-18 - CVE-2026-61633 published to NVD
- 2026-09-18 - Last updated in NVD database
Technical Details for CVE-2026-61633
Vulnerability Analysis
The flaw is an infinite loop condition classified as [CWE-835] (Loop with Unreachable Exit Condition). The nni_mqtt_msg_decode_unsubscribe() function iterates through topic entries in an UNSUBSCRIBE packet using buf.curpos and buf.endpos as loop boundaries. When read_uint16() fails on malformed input, the function does not propagate the error. Instead, the loop continues with buf.curpos unchanged while incrementing topic_count. This creates a non-terminating parse cycle that consumes CPU cycles and accumulates memory allocations tied to the fabricated topic count.
MQTT 3.1.1 clients that enable automatic reconnection amplify the impact. Each reconnect attempt to the malicious broker reproduces the hang, resulting in sustained service degradation on the client host.
Root Cause
The root cause is missing return-value validation on read_uint16() inside the UNSUBSCRIBE decode loop. When the read fails on a zero-length topic followed by trailing bytes, the parser advances internal counters without advancing the buffer cursor. The exit condition buf.curpos < buf.endpos is never satisfied, producing the unreachable exit state.
Attack Vector
Exploitation requires a client to connect to an attacker-controlled MQTT broker. The broker sends a crafted UNSUBSCRIBE frame containing a zero-length topic followed by trailing data. Because attack success depends on the client initiating the connection and processing the malformed packet, the attack complexity is high and requires user interaction. Only client-side parsing is affected; broker-side decoding via nmq_unsubinfo_decode remains safe.
// Security patch in src/supplemental/mqtt/mqtt_codec.c
saved_current_pos = buf.curpos;
while (buf.curpos < buf.endpos) {
ret = read_uint16(&buf, &temp_length);
+ if (ret != MQTT_SUCCESS) {
+ return MQTT_ERR_PROTOCOL;
+ }
/* jump to the end of topic-name */
buf.curpos += temp_length;
/* skip QoS field */
Source: GitHub Commit fa8d859
Detection Methods for CVE-2026-61633
Indicators of Compromise
- NanoMQ client processes exhibiting sustained 100% CPU utilization shortly after connecting to a remote broker
- Rapidly growing resident memory on hosts running NanoMQ client binaries prior to 0.24.14
- Repeated MQTT 3.1.1 CONNECT attempts followed by unresponsive client state when automatic reconnect is enabled
Detection Strategies
- Inventory installed NanoMQ and NanoNNG library versions and flag anything below 0.24.14
- Inspect MQTT traffic for UNSUBSCRIBE packets containing zero-length topic fields followed by trailing bytes
- Correlate MQTT client crashes or hangs with connections to untrusted or newly observed broker endpoints
Monitoring Recommendations
- Alert on process-level CPU or memory thresholds for MQTT client workloads on Internet of Things (IoT) gateways
- Log outbound MQTT connections and validate broker endpoints against an allowlist
- Monitor for repeated reconnect loops emitted by NanoMQ clients toward the same broker
How to Mitigate CVE-2026-61633
Immediate Actions Required
- Upgrade NanoMQ and NanoNNG to version 0.24.14 or later on all client hosts
- Restrict MQTT client connections to trusted, authenticated broker endpoints only
- Disable automatic reconnection until patched to limit repeated denial of service cycles
Patch Information
The fix is included in NanoMQ release 0.24.14. The upstream patch in NanoNNG pull request 1518 validates the read_uint16() return value and aborts decoding with MQTT_ERR_PROTOCOL when the read fails. Additional detail is available in GitHub Security Advisory GHSA-m7mp-rr3v-hmhr.
Workarounds
- Route MQTT client traffic through a broker allowlist to block connections to untrusted brokers
- Terminate client processes and disable auto-reconnect when abnormal CPU or memory growth is detected
- Apply the upstream patch from commit fa8d859 if binary upgrades to 0.24.14 are not yet feasible
# Verify installed NanoMQ version and upgrade
nanomq --version
# Upgrade to patched release
git clone --branch 0.24.14 https://github.com/nanomq/nanomq.git
cd nanomq && mkdir build && cd build
cmake .. && make && sudo make install
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
