Skip to main content
Vulnerability Database/CVE-2026-73863

CVE-2026-73863: NanoMQ MQTT Broker DOS Vulnerability

CVE-2026-73863 is a denial of service flaw in NanoMQ MQTT broker that allows remote attackers to crash the broker through malformed SUBSCRIBE packets. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-73863 Overview

NanoMQ, an open-source MQTT broker, contains an out-of-bounds read vulnerability [CWE-125] in its MQTT v5 property decoder. The flaw resides in the nmq_subinfo_decode() function within nng/src/sp/protocol/mqtt/mqtt_parser.c. A remote client can send a crafted SUBSCRIBE packet with a multi-byte Properties Length and repeated SUBSCRIPTION_IDENTIFIER entries to trigger a read beyond the heap message buffer. The condition is reachable through the broker receive path without authentication and can crash the broker process. The issue is fixed in NanoMQ version 0.24.14.

Critical Impact

An unauthenticated remote attacker can crash the NanoMQ broker by sending a single malformed MQTT v5 SUBSCRIBE packet, disrupting all MQTT-dependent services.

Affected Products

  • NanoMQ broker versions prior to 0.24.14
  • NanoNNG library (MQTT parser component) prior to the fix commit f888fe3
  • MQTT v5 broker deployments exposing the receive path to untrusted clients

Discovery Timeline

  • 2026-09-18 - CVE-2026-73863 published to the National Vulnerability Database
  • 2026-09-24 - Last updated in NVD database

Technical Details for CVE-2026-73863

Vulnerability Analysis

The vulnerability affects the MQTT v5 property decoding path in NanoMQ's broker-side subscription handler. When parsing a SUBSCRIBE packet, nmq_subinfo_decode() iterates over properties contained in the packet's Properties block. For each SUBSCRIPTION_IDENTIFIER property, the parser calls get_var_integer() to decode a variable-length integer value.

The defect lies in variable reuse. The parser reuses len_of_varint, a variable previously assigned when decoding the outer Properties Length field, instead of capturing the length consumed by each per-property varint decode. Consequently, pos is advanced by an incorrect number of bytes, and subsequent iterations dereference memory past the end of the heap-allocated MQTT message buffer.

Because parsing occurs before any application-level authorization enforcement on the packet payload, no credentials or prior session state are required to trigger the flaw. Reading past the buffer boundary causes the broker to crash, resulting in denial of service for all connected MQTT clients.

Root Cause

The root cause is an incorrect offset accumulator in nmq_subinfo_decode(). The SUBSCRIPTION_IDENTIFIER case passed the stale outer len_of_varint variable to advance pos, rather than a local length receiver populated by the inner get_var_integer() call. Repeating SUBSCRIPTION_IDENTIFIER properties amplifies the drift until pos points outside the allocated message buffer.

Attack Vector

A remote attacker connects to the broker's MQTT listener and sends a MQTT v5 SUBSCRIBE packet whose Properties block encodes the Properties Length as a multi-byte varint and contains multiple SUBSCRIPTION_IDENTIFIER properties. The broker parses the packet through nmq_subinfo_decode(), mis-advances the read cursor, and issues an out-of-bounds read that terminates the process.

c
// Patch from src/sp/protocol/mqtt/mqtt_parser.c
// Source: https://github.com/nanomq/NanoNNG/commit/f888fe39d6691b253ff9aee598ce58bbe449ab6f
 			len_of_str = 0;
 			break;
 		case SUBSCRIPTION_IDENTIFIER:
-			subid = get_var_integer(var_ptr + pos, &len_of_varint);
+			uint8_t prop_varint_len = 0;
+			subid = get_var_integer(var_ptr + pos, &prop_varint_len);
 			if (subid == 0)
 				return (-1);
-			pos += len_of_varint;
+			pos += prop_varint_len;
 			break;
 		default:
 			log_error("Invalid property id");

The fix introduces a local prop_varint_len variable to correctly track the bytes consumed by each per-property varint decode.

Detection Methods for CVE-2026-73863

Indicators of Compromise

  • Unexpected termination or segmentation faults of the nanomq broker process shortly after a client connection
  • MQTT v5 SUBSCRIBE packets containing multi-byte encoded Properties Length combined with multiple SUBSCRIPTION_IDENTIFIER (0x0B) properties
  • Repeated broker restarts logged by the service supervisor without corresponding operator action

Detection Strategies

  • Inspect MQTT traffic at the network layer for SUBSCRIBE packets (control packet type 8) whose Properties Length uses more than one varint byte and contains multiple SUBSCRIPTION_IDENTIFIER properties
  • Enable core-dump collection on broker hosts to capture crash artifacts pointing at nmq_subinfo_decode() or get_var_integer() in the call stack
  • Correlate broker crash events with the source IP of the last SUBSCRIBE packet processed before termination

Monitoring Recommendations

  • Alert on any restart of the NanoMQ service outside scheduled maintenance windows
  • Track MQTT connection churn per client identifier and source IP to detect scan-and-crash behavior
  • Forward broker stderr and log_error() output to centralized logging for parser-error visibility

How to Mitigate CVE-2026-73863

Immediate Actions Required

  • Upgrade NanoMQ to version 0.24.14 or later, which contains the fix commit f888fe3
  • Restrict broker exposure by placing MQTT listeners behind network ACLs or a VPN until patching is complete
  • Enforce client authentication and TLS on all listeners to reduce the pool of parties able to reach the parser

Patch Information

The fix is included in the NanoMQ 0.24.14 release. Technical details are documented in GitHub Security Advisory GHSA-pf97-vm7h-q84m and the upstream pull request discussion. Operators building from source should rebase onto the fix commit in NanoNNG.

Workarounds

  • Terminate MQTT v5 connections at an intermediary broker or proxy that validates Properties parsing before forwarding
  • Configure firewall rules to allow only known client IP ranges to reach the broker's MQTT ports (default 1883/8883)
  • Disable MQTT v5 protocol support on the listener where feasible, restricting clients to MQTT v3.1.1
bash
# Verify installed NanoMQ version and upgrade
nanomq --version

# Example: build and install NanoMQ 0.24.14 from source
git clone --branch 0.24.14 https://github.com/nanomq/nanomq.git
cd nanomq && git submodule update --init --recursive
mkdir build && cd build
cmake -G Ninja ..
sudo ninja install

# Restrict listener exposure via host firewall (Linux/nftables example)
sudo nft add rule inet filter input tcp dport {1883, 8883} ip saddr != 10.0.0.0/8 drop

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.