CVE-2026-42209 Details
Description
FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.26.1, a remote client with retained publish permission can crash the FlashMQ broker when both set_retained_message_defer_timeout and set_retained_message_defer_timeout_spread are configured to non-default values, resulting in denial of service. If anonymous retained publishing is allowed, no authentication is required; otherwise, the attacker needs the corresponding publish permission. This issue has been patched in version 1.26.1.
A denial-of-service vulnerability has been identified in FlashMQ, an MQTT broker, prior to version 1.26.1. The issue arises when a remote client with retained publish permission crashes the broker by exploiting the retained-message deferred write process. This exploitation requires the 'set_retained_message_defer_timeout' and 'set_retained_message_defer_timeout_spread' settings to be configured to non-default values. If anonymous retained publishing is permitted, no authentication is needed; otherwise, the attacker must have the appropriate publish rights.
Users can upgrade to FlashMQ version 1.26.1, which addresses the division-by-zero crash in the deferred retained message handling. After updating, a configuration reload is required to apply the changes.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 8, 2026CISA-ADP
Assessed May 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/halfgaar/FlashMQ/issues/167 | CISA-ADP | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/halfgaar/FlashMQ/commit/193b6e7767889511cfa8e933908ea5e6a1077a1f | [email protected] | Source CodeVendor |
| https://github.com/halfgaar/FlashMQ/issues/167 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/halfgaar/FlashMQ/releases/tag/v1.26.1 | [email protected] | Release NotesVendor |
| https://github.com/halfgaar/FlashMQ/security/advisories/GHSA-2789-vfcg-5922 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-369 | Divide By Zero | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| halfgaar FlashMQ | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 11, 2026 | CVE Modified | CISA-ADP |
| May 8, 2026 | New CVE Received | [email protected] |
Volerion