CVE-2026-26446
Description
A flaw was found in Stomper. An unauthenticated client can trigger a denial of service by closing their TCP connection at specific points while a broker is sending data. This action causes the server process to receive a SIGPIPE signal, leading to its immediate termination and a denial of service for legitimate users.
Statement
A Denial of Service flaw was found in Stomper. An unauthenticated remote client can trigger an unhandled SIGPIPE signal by prematurely closing its TCP connection while the server is writing data to the socket. Because the process fails to ignore or handle SIGPIPE during active write operations, the daemon terminates abruptly. Red Hat default security controls (such as process isolation and systemd service auto-restart directives) restrict the failure strictly to an availability impact on the message broker service, without allowing privilege escalation or memory corruption.
Mitigation
Configure network firewalls or ingress access controls to limit access to the STOMP server port strictly to trusted IP addresses. Alternatively, run the broker within a process manager or container platform configured to automatically restart the service upon abrupt termination.
Understanding the Weakness (CWE)
Availability,Confidentiality
Technical Impact: DoS: Crash, Exit, or Restart; Read Application Data
An uncaught exception could cause the system to be placed in a state that could lead to a crash, exposure of sensitive information or other unintended behaviors.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.