Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Ruoyyy

#42661of 55,140
6.5Total CVSS
Vulnerabilities · 1
PT-2026-39199
6.5
2026-05-08
Flashmq · Flashmq · CVE-2026-42209
**Name of the Vulnerable Software and Affected Versions** FlashMQ versions prior to 1.26.1 **Description** A remote client with retained publish permission can cause a denial of service by crashing the broker. This occurs when both `set retained message defer timeout` and `set retained message defer timeout spread` are configured to non-default values. If anonymous retained publishing is enabled, no authentication is required to trigger the crash; otherwise, the attacker must possess the necessary publish permissions. **Recommendations** Update to version 1.26.1.