CVE-2024-36856: Rmqtt

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

RMQTT Broker 0.4.0 is vulnerable to Denial of Service (DoS) due to improper session resource management. An attacker can exhaust system memory and crash the daemon by establishing and maintaining a vast number of long-lived malicious publish/subscribe sessions.

Affected products

  • Rmqtt Rmqtt: version 0.4.0 only

Published 2024-06-12. Last modified 2026-06-17.