Back

HIGH

stomper: stomper: Denial of Service via partial STOMP frames

Published Aug 26, 2026

Description

stomper 5e2741e is vulnerable to Denial of Service. A malicious client can send partial STOMP frames and keep the TCP connections open, which, combined with the broker s use of edge-triggered epoll (EPOLLET) and MSG_PEEK in recv(), causes sockets to enter a permanent half-read state. When enough such connections accumulate, the broker stops receiving any further epoll events for those sockets and eventually hangs in epoll_wait, effectively refusing to process new messages.

Affected products

Remediation

Red Hat statement

A flaw was found in stomper. A remote unauthenticated attacker can cause a Denial of Service by sending partial STOMP frames over open TCP connections. When combined with the broker's use of edge-triggered epoll (EPOLLET) and MSG_PEEK in recv(), sockets enter a permanent half-read state. Once enough connections accumulate, the broker stops receiving epoll events for these sockets and hangs in epoll_wait, refusing new messages. Red Hat default security controls (e.g., non-root execution, process isolation) do not prevent this service-level socket starvation, though network boundaries can limit exposure.

Red Hat mitigation

Limit exposure by configuring network firewalls or security groups to restrict access to the STOMP broker port only to trusted clients. Alternatively, reduce the connection timeout and limit the maximum allowed unauthenticated TCP connections per host at the infrastructure or ingress layer.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 26, 2026
Updated Sep 2, 2026
Reserved Feb 16, 2026
CISA Vulnrichment
Updated Sep 2, 2026
NVD
Status Deferred
Modified Sep 2, 2026
Red Hat
Severity Important
Public date Aug 26, 2026
ENISA EUVD
Assigner mitre
Published Aug 26, 2026
Updated Sep 2, 2026
Exploited since n/a
EUVD-2026-66756