CVE-2026-26446

Stomper 5e2741e is vulnerable to Denial of Service. When a broker sends data to a client whose TCP connection was already closed by the peer, the server process receives SIGPIPE and immediately terminates, resulting in a denial of service. Any unauthenticated client can trigger the crash by closing the socket at specific points.

  • Published Aug 26, 2026
  • CVSS 7.5 high
  • 0.5% chance of exploitation in the next 30 days (EPSS)

CVE-2026-26446 at the National Vulnerability Database