Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-26446

Опубликовано: 26 авг. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Stomper 5e2741e is vulnerable to Denial of Service. When a broker sends data to a client whose TCP connection was already closed by the peer, the server process receives SIGPIPE and immediately terminates, resulting in a denial of service. Any unauthenticated client can trigger the crash by closing the socket at specific points.

A flaw was found in Stomper. An unauthenticated client can trigger a denial of service by closing their TCP connection at specific points while a broker is sending data. This action causes the server process to receive a SIGPIPE signal, leading to its immediate termination and a denial of service for legitimate users.

Отчет

A Denial of Service flaw was found in Stomper. An unauthenticated remote client can trigger an unhandled SIGPIPE signal by prematurely closing its TCP connection while the server is writing data to the socket. Because the process fails to ignore or handle SIGPIPE during active write operations, the daemon terminates abruptly. Red Hat default security controls (such as process isolation and systemd service auto-restart directives) restrict the failure strictly to an availability impact on the message broker service, without allowing privilege escalation or memory corruption.

Меры по смягчению последствий

Configure network firewalls or ingress access controls to limit access to the STOMP server port strictly to trusted IP addresses. Alternatively, run the broker within a process manager or container platform configured to automatically restart the service upon abrupt termination.

Дополнительная информация

Статус:

Important
Дефект:
CWE-248
https://bugzilla.redhat.com/show_bug.cgi?id=2524664stomper: Stomper: Denial of Service due to improper handling of closed TCP connections

EPSS

Процентиль: 28%
0.00343
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
22 дня назад

Stomper 5e2741e is vulnerable to Denial of Service. When a broker sends data to a client whose TCP connection was already closed by the peer, the server process receives SIGPIPE and immediately terminates, resulting in a denial of service. Any unauthenticated client can trigger the crash by closing the socket at specific points.

CVSS3: 7.5
nvd
22 дня назад

Stomper 5e2741e is vulnerable to Denial of Service. When a broker sends data to a client whose TCP connection was already closed by the peer, the server process receives SIGPIPE and immediately terminates, resulting in a denial of service. Any unauthenticated client can trigger the crash by closing the socket at specific points.

CVSS3: 7.5
github
21 день назад

Stomper 5e2741e is vulnerable to Denial of Service. When a broker sends data to a client whose TCP connection was already closed by the peer, the server process receives SIGPIPE and immediately terminates, resulting in a denial of service. Any unauthenticated client can trigger the crash by closing the socket at specific points.

EPSS

Процентиль: 28%
0.00343
Низкий

7.5 High

CVSS3