FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.26.1, a remote client with retained publish permission can crash the FlashMQ broker when both setretainedmessagedefertimeout and setretainedmessagedefertimeout_spread are configured to non-default values, resulting in denial of service. If anonymous retained publishing is allowed, no authentication is required; otherwise, the attacker needs the corresponding publish permission. This issue has been patched in version 1.26.1.
{
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42209.json",
"cwe_ids": [
"CWE-369"
]
}"2026-08-12T16:24:18Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-42209.json"
[
{
"target": {
"file": "subscriptionstore.cpp"
},
"id": "CVE-2026-42209-e6337151",
"signature_type": "Line",
"source": "https://github.com/halfgaar/flashmq/commit/193b6e7767889511cfa8e933908ea5e6a1077a1f",
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"138165048839958869210583791425133712750",
"22018605384051317281846779510216209006",
"50972820445124572842254708106828772164",
"308506853646627152287636873492342340212",
"52595365389558395055774363130953779106"
]
}
}
]