PT-2025-43673 · Flashmq · Flashmq

Published

2025-10-24

·

Updated

2025-10-24

·

CVE-2025-62723

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions FlashMQ versions prior to 1.23.2
Description FlashMQ, a MQTT broker/server designed for multi-CPU environments, has an issue where authenticated users can create sessions that collect Quality of Service (QoS) messages. These messages are not released when sessions expire, leading to potential resource exhaustion.
Recommendations Update to version 1.23.2 or later.

Exploit

Fix

Missing Release of Resource after Effective Lifetime

Weakness Enumeration

Related Identifiers

CVE-2025-62723
GHSA-7MHP-22Q4-R6VV

Affected Products

Flashmq