PT-2026-41527 · Emqx · Emqx
Cccaaa
·
Published
2026-05-17
·
Updated
2026-05-20
·
CVE-2026-8741
CVSS v3.1
3.1
Low
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
EMQX versions prior to 6.2.0
Description
A race condition exists in the QoS 2 PUBLISH Packet Handler component within the
apps/emqx/src/emqx persistent session ds.erl file. This issue allows a remote attacker to trigger a race condition, which occurs when the system's substantive behavior is dependent on the sequence or timing of other uncontrollable events. This attack is characterized by high complexity and is difficult to exploit.Recommendations
Update to a version later than 6.2.0.
As a temporary workaround, restrict access to the QoS 2 PUBLISH Packet Handler component to minimize the risk of exploitation.
Exploit
Fix
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Emqx