Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-26448

Опубликовано: 26 авг. 2026
Источник: redhat
CVSS3: 7.5

Описание

Stomper 5e2741e is vulnerable to Use-After-Free. When a client sends multiple CONNECT frames on the same TCP connection, and subsequently another client (or a later connection) sends SEND frames to a destination previously subscribed on that connection, the broker may dereference a pointer to a StompStreamSocket object that has already been freed. This results in a heap use-after-free and process crash. Because the protocol does not authenticate or restrict such sequences by default.

A flaw was found in Stomper. A remote attacker can trigger a use-after-free vulnerability by sending multiple CONNECT frames on the same TCP connection, followed by SEND frames to a previously subscribed destination. This can cause the broker to dereference a freed memory region, leading to a heap use-after-free and a process crash, resulting in a Denial of Service (DoS).

Отчет

A heap use-after-free flaw was found in Stomper. A remote, unauthenticated attacker can exploit this by issuing multiple CONNECT frames on a single TCP connection, followed by SEND frames directed to a previously subscribed destination. This sequence causes the broker to dereference a freed StompStreamSocket object, triggering a heap corruption and crashing the broker process. Red Hat default security controls (such as process isolation and non-root execution boundaries) constrain the issue to a Denial of Service against the messaging daemon, preventing arbitrary code execution.

Меры по смягчению последствий

Restrict access to the STOMP message broker port using firewall rules or network security groups to allow traffic only from authorized, trusted IP addresses. Where supported by network boundaries or ingress control layers, enforce strict limits on repeated frame sequences and connection lifetimes per host.

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2524660stomper: Stomper: Denial of Service via Use-After-Free

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
22 дня назад

Stomper 5e2741e is vulnerable to Use-After-Free. When a client sends multiple CONNECT frames on the same TCP connection, and subsequently another client (or a later connection) sends SEND frames to a destination previously subscribed on that connection, the broker may dereference a pointer to a StompStreamSocket object that has already been freed. This results in a heap use-after-free and process crash. Because the protocol does not authenticate or restrict such sequences by default.

CVSS3: 9.8
nvd
22 дня назад

Stomper 5e2741e is vulnerable to Use-After-Free. When a client sends multiple CONNECT frames on the same TCP connection, and subsequently another client (or a later connection) sends SEND frames to a destination previously subscribed on that connection, the broker may dereference a pointer to a StompStreamSocket object that has already been freed. This results in a heap use-after-free and process crash. Because the protocol does not authenticate or restrict such sequences by default.

CVSS3: 9.8
github
21 день назад

Stomper 5e2741e is vulnerable to Use-After-Free. When a client sends multiple CONNECT frames on the same TCP connection, and subsequently another client (or a later connection) sends SEND frames to a destination previously subscribed on that connection, the broker may dereference a pointer to a StompStreamSocket object that has already been freed. This results in a heap use-after-free and process crash. Because the protocol does not authenticate or restrict such sequences by default.

7.5 High

CVSS3