CVE-2026-26446
Description
AI Translation Available
Stomper 5e2741e is vulnerable to Denial of Service. When a broker sends data to a client whose TCP connection was already closed by the peer, the server process receives SIGPIPE and immediately terminates, resulting in a denial of service. Any unauthenticated client can trigger the crash by closing the socket at specific points.
https://github.com/mdoi/stomper
https://github.com/songxpu/bug_report/blob/master/Stomp/stomper_vuln2.md