๐Ÿ” CVE Alert

CVE-2026-46411

MEDIUM 6.5

FlashMQ: Client can trigger uncaught exception on FlashMQ 1.26.1 and older

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.26.2, authorized clients have the ability to exceed the permitted over-commit of their write buffer and triggering an internal safe-guard exception. This exception was in a path that was not catchable, and therefore causes a server abort. This issue has been patched in version 1.26.2.

CWE CWE-248
Vendor halfgaar
Product flashmq
Published Jun 9, 2026
Stay Ahead of the Next One

Get instant alerts for halfgaar flashmq

Be the first to know when new medium vulnerabilities affecting halfgaar flashmq are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

halfgaar / FlashMQ
< 1.26.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/halfgaar/FlashMQ/security/advisories/GHSA-g35r-265r-rxrh github.com: https://github.com/halfgaar/FlashMQ/commit/29e08f7b97b6e3f96db923c2b6a260c47b49c195 github.com: https://github.com/halfgaar/FlashMQ/releases/tag/v1.26.2