Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-26447

Опубликовано: 26 авг. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Stomper 5e2741e is vulnerable to Use-After-Free. When a single client repeatedly issues SUBSCRIBE commands for the same destination over one connection and then closes that connection, the broker performs incorrect cleanup of its internal subscription structures. This results in a heap use-after-free during StompClient destruction, causing the broker process to crash. An unauthenticated client can exploit this to reliably trigger a denial of service.

EPSS

Процентиль: 28%
0.00343
Низкий

7.5 High

CVSS3

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 7.5
ubuntu
21 день назад

(Stomper 5e2741e is vulnerable to Use-After-Free. When a single client ...)

CVSS3: 7.5
github
21 день назад

Stomper 5e2741e is vulnerable to Use-After-Free. When a single client repeatedly issues SUBSCRIBE commands for the same destination over one connection and then closes that connection, the broker performs incorrect cleanup of its internal subscription structures. This results in a heap use-after-free during StompClient destruction, causing the broker process to crash. An unauthenticated client can exploit this to reliably trigger a denial of service.

EPSS

Процентиль: 28%
0.00343
Низкий

7.5 High

CVSS3

Дефекты

CWE-416