CVE-2024-48077

NanoMQ v0.22.7 is vulnerable to Denial of Service (DoS) due to improper resource throttling. A crafted sequence of requests causes the recv-q queue to saturate, leading to the rapid exhaustion of system file descriptors (FDs). This exhaustion triggers a process crash, rendering the broker unable to provide services.
Configurations

Configuration 1 (hide)

cpe:2.3:a:emqx:nanomq:0.22.7:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-01-15 20:16

Updated : 2026-06-17 07:58


NVD link : CVE-2024-48077

Mitre link : CVE-2024-48077

CVE.ORG link : CVE-2024-48077


JSON object : View

Products Affected

emqx

  • nanomq
CWE
CWE-400

Uncontrolled Resource Consumption

CWE-833

Deadlock