CVE-2025-65953
Last modified
CVE-2025-65953 is a medium-severity vulnerability rated 6/10 on the CVSS scale. NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.22.5, a Heap-Use-After-Free (UAF) vulnerability exists in the TCP transport component of NanoMQ, which relies on the underlying NanoNNG library (specifically in src/sp/transport/mqtt/broker_tcp.c). EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.22.5, a Heap-Use-After-Free (UAF) vulnerability exists in the TCP transport component of NanoMQ, which relies on the underlying NanoNNG library (specifically in src/sp/transport/mqtt/broker_tcp.c). The vulnerability is due to improper resource management and premature cleanup of message and pipe structures under specific malformed MQTTV5 retain message traffic conditions. This issue has been patched in version 0.22.5.
Metrics
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-65953?
How severe is CVE-2025-65953?
How do I fix CVE-2025-65953?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-65946Roo Code is an AI-powered autonomous coding agent that lives…8.1
- CVE-2025-65947thread-amount is a tool that gets the amount of threads in t…8.7
- CVE-2025-6595Improper Neutralization of Input During Web Page Generation …4.7
- CVE-2025-65950WBCE CMS is a content management system. In versions 1.6.4 a…8.8
- CVE-2025-65951Inside Track / Entropy Derby is a research-grade horse-racin…8.7
- CVE-2025-65952Console is a network used to control Gorilla Tag mods' users…8.7
- CVE-2025-65954SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS s…6.1
- CVE-2025-65955ImageMagick is free and open-source software used for editin…6.1
- CVE-2025-65956Formwork is a flat file-based Content Management System (CMS…5.4
- CVE-2025-65957Core Bot Is an Open Source discord bot made for maple hospit…8.8
- CVE-2025-65958Open WebUI is a self-hosted artificial intelligence platform…7.1
- CVE-2025-65959Open WebUI is a self-hosted artificial intelligence platform…5.4
Are you affected by CVE-2025-65953?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
