FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.23.2, any authenticated user can create sessions and have them collect QoS messages. When not sent to a client, these are then not released upon (eventual) session expiration. Version 1.23.2 fixes the issue.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 31 Oct 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:flashmq:flashmq:*:*:*:*:*:*:*:* |
Mon, 27 Oct 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Flashmq
Flashmq flashmq |
|
| Vendors & Products |
Flashmq
Flashmq flashmq |
Fri, 24 Oct 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.23.2, any authenticated user can create sessions and have them collect QoS messages. When not sent to a client, these are then not released upon (eventual) session expiration. Version 1.23.2 fixes the issue. | |
| Title | FlashMQ does not release memory of queued QoS messages | |
| Weaknesses | CWE-772 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-10-24T20:32:00.596Z
Reserved: 2025-10-20T19:41:22.741Z
Link: CVE-2025-62723
No data.
Status : Analyzed
Published: 2025-10-24T21:16:14.010
Modified: 2025-10-31T19:31:48.540
Link: CVE-2025-62723
No data.
OpenCVE Enrichment
Updated: 2025-10-27T22:10:30Z
Weaknesses