Executive brief
FlashMQ is a high-performance message broker used to route data between devices in multi-CPU environments. A vulnerability exists where a remote user can crash the server by sending a specific type of message, leading to a total service outage. This occurs only when certain non-default performance settings are enabled. If the server is configured to allow anonymous messages, no login is required to trigger the crash; otherwise, an attacker needs basic publishing permissions.
Technical details
A division-by-zero error (CWE-369) exists in the 'SubscriptionStore::trySetRetainedMessages' function of FlashMQ. The vulnerability is triggered when 'set_retained_message_defer_timeout' is non-zero and 'set_retained_message_defer_timeout_spread' is configured to a non-default value (specifically zero), leading to a modulo operation by zero during timeout calculation. An attacker with 'retained publish' permissions can exploit this over the network to crash the broker process. If anonymous publishing is enabled, the attack requires no authentication. The issue is fixed in version 1.26.1 by adding a check for zero-value spreads before performing the calculation.
Affected products
- halfgaar FlashMQ < 1.26.1
Timeline
- 2026-04-20: patched: Version 1.26.1 released
- 2026-05-08: disclosed: Initial advisory publication