Impact
The Stomper broker is vulnerable to a use‑after‑free condition that occurs when a client repeatedly sends SUBSCRIBE commands for the same destination on a single connection and then closes that connection. The broker’s cleanup logic fails to correctly free internal subscription structures, leading to a heap use‑after‑free during the destruction of the client object. An unauthenticated attacker can trigger this flaw systematically to crash the broker process, resulting in a denial of service. The weakness is a classic use‑after‑free that compromises the integrity and availability of the broker.
Affected Systems
The affected product is the Stomper broker, version 5e2741e. Vendor information is not disclosed in the advisory. No other products or versions are identified.
Risk and Exploitability
This vulnerability can be exploited remotely by any network user that can communicate with the broker, as it does not require authentication. The exploit reliably causes the broker to terminate, providing a simple denial‑of‑service attack vector. The CVSS score of 7.5 indicates a high severity, and the EPSS score of < 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV database.
OpenCVE Enrichment