CVE-2024-36856

RMQTT Broker 0.4.0 is vulnerable to Denial of Service (DoS) due to improper session resource management. An attacker can exhaust system memory and crash the daemon by establishing and maintaining a vast number of long-lived malicious publish/subscribe sessions.
Configurations

No configuration.

History

03 Apr 2026, 16:16

Type Values Removed Values Added
Summary (en) RMQTT Broker 0.4.0 allows remote attackers to cause a Denial of Service (daemon crash) via a large number of malicious packets. (en) RMQTT Broker 0.4.0 is vulnerable to Denial of Service (DoS) due to improper session resource management. An attacker can exhaust system memory and crash the daemon by establishing and maintaining a vast number of long-lived malicious publish/subscribe sessions.

15 Jan 2026, 17:16

Type Values Removed Values Added
Summary (en) RMQTT Broker 0.4.0 allows remote attackers to cause a Denial of Service (daemon crash) via a certain sequence of five TCP packets. (en) RMQTT Broker 0.4.0 allows remote attackers to cause a Denial of Service (daemon crash) via a large number of malicious packets.

21 Nov 2024, 09:22

Type Values Removed Values Added
References () https://gist.github.com/pengwGit/d8410afeb0d5d11ab79f596a32178c2e - () https://gist.github.com/pengwGit/d8410afeb0d5d11ab79f596a32178c2e -
References () https://github.com/rmqtt/rmqtt/releases/tag/0.4.0 - () https://github.com/rmqtt/rmqtt/releases/tag/0.4.0 -

22 Aug 2024, 19:35

Type Values Removed Values Added
CWE CWE-404
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

13 Jun 2024, 18:36

Type Values Removed Values Added
Summary
  • (es) RMQTT Broker 0.4.0 permite a atacantes remotos provocar una denegación de servicio (caída del daemon) a través de una determinada secuencia de cinco paquetes TCP.

12 Jun 2024, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-12 03:15

Updated : 2026-04-15 00:35


NVD link : CVE-2024-36856

Mitre link : CVE-2024-36856

CVE.ORG link : CVE-2024-36856


JSON object : View

Products Affected

No product.

CWE
CWE-404

Improper Resource Shutdown or Release