PT-2026-82273 · Canonical · Stomper

CVE-2026-26448

·

Published

2026-08-26

·

Updated

2026-08-26

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Stomper version 5e2741e
Description A Use-After-Free issue occurs when a client sends multiple CONNECT frames on the same TCP connection, followed by another client or connection sending SEND frames to a destination previously subscribed on that connection. This causes the broker to dereference a pointer to a StompStreamSocket object that has already been freed, leading to a heap use-after-free and a process crash. This is possible because the protocol does not authenticate or restrict these sequences by default.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-26448

Affected Products

Stomper