CVE-2024-48077

A

n issue in nanomq v0.22.7 allows attackers to cause a Denial of Service (DoS) via a crafted request. The number of data packets received in the recv-q queue of the Nanomq process continues to increase, causing the nanomq broker to fall into a deadlock and be unable to provide normal services.

Configurations

Configuration 1 (hide)

cpe:2.3:a:emqx:nanomq:0.22.7:*:*:*:*:*:*:*

History

23 Jan 2026, 19:06

Type Values Removed Values Added
First Time Emqx nanomq
Emqx
References () https://gist.github.com/pengwGit/2379e7a8fe75d09621f7c060db0237c4 - () https://gist.github.com/pengwGit/2379e7a8fe75d09621f7c060db0237c4 - Third Party Advisory
References () https://github.com/nanomq/nanomq - () https://github.com/nanomq/nanomq - Product
CPE cpe:2.3:a:emqx:nanomq:0.22.7:*:*:*:*:*:*:*

15 Jan 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-15 20:16

Updated : 2026-01-23 19:06


NVD link : CVE-2024-48077

Mitre link : CVE-2024-48077

CVE.ORG link : CVE-2024-48077


JSON object : View

Products Affected
CWE
CWE-400

Uncontrolled Resource Consumption

CWE-833

Deadlock