PT-2026-82270 · Canonical · Stomper

CVE-2026-26445

·

Published

2026-08-26

·

Updated

2026-08-26

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions stomper version 5e2741e
Description A Denial of Service issue exists where a malicious client can send partial STOMP frames and maintain open TCP connections. This occurs because the broker utilizes edge-triggered epoll (EPOLLET) and MSG PEEK in the recv() function, leading sockets to enter a permanent half-read state. As these connections accumulate, the broker ceases to receive epoll events for those sockets and hangs in epoll wait(), preventing the processing of new messages.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-26445

Affected Products

Stomper