{"apiVersion":"1.0","identifier":"CVE-2026-26445","description":"stomper 5e2741e is vulnerable to Denial of Service. A malicious client can send partial STOMP frames and keep the TCP connections open, which, combined with the broker s use of edge-triggered epoll (EPOLLET) and MSG_PEEK in recv(), causes sockets to enter a permanent half-read state. When enough such connections accumulate, the broker stops receiving any further epoll events for those sockets and eventually hangs in epoll_wait, effectively refusing to process new messages.","publishedAt":"2026-08-26T20:17:11","lastModifiedAt":"2026-08-26T20:17:11","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-26445","cvssScore":null,"cvssVector":"Pending","epssProbability":0.00155,"riskScore":0,"affectedProduct":"stomper","affectedVersions":"cannotmatch","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-26445","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-26445","en":"https://www.redsauce.net/en/cves/CVE-2026-26445","fr":"https://www.redsauce.net/fr/cves/CVE-2026-26445","pt":"https://www.redsauce.net/pt/cves/CVE-2026-26445","de":"https://www.redsauce.net/de/cves/CVE-2026-26445","sk":"https://www.redsauce.net/sk/cves/CVE-2026-26445","el":"https://www.redsauce.net/el/cves/CVE-2026-26445"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-26445"}}