CVE-2025-62723: medium-severity vulnerability in halfgaar FlashMQ
FlashMQ does not release memory of queued QoS messages
Published
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 4.3epss 0.3%
exploitation probability
0.3%top 75% of all CVEs
observed exploitation
nono source reports it
FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.23.2, any authenticated user can create sessions and have them collect QoS messages. When not sent to a client, these are then not released upon (eventual) session expiration. Version 1.23.2 fixes the issue.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Affected products
halfgaar · FlashMQRelated CVEs — halfgaar FlashMQ
In the same product, most dangerous first.