Use After Free Affecting emqx/nanomq package, versions [,0.24.11)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.22% (13th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Use After Free vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-UNMANAGED-EMQXNANOMQ-15440483
  • published8 Mar 2026
  • disclosed5 Mar 2026
  • creditUnknown

Introduced: 5 Mar 2026

CVE-2026-22040  (opens in a new tab)
CWE-416  (opens in a new tab)

How to fix?

Upgrade emqx/nanomq to version 0.24.11 or higher.

Overview

Affected versions of this package are vulnerable to Use After Free in the broker process when handling a combined pattern of high-frequency publishes, rapid reconnects or kick-outs using the same ClientID, and significant subscribe/unsubscribe jitter. An attacker can cause heap memory corruption and force the broker to crash by manipulating client connections and message traffic in this manner.

CVSS Base Scores

version 4.0
version 3.1