Flashmq is a message broker implementing the MQTT protocol, with its vulnerability footprint centered on this single application and characterized by resource-management and assertion-handling weaknesses such as reachable assertions and missing resource releases. These classes reflect the complexities of long-lived network services managing client connections and memory state; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flashmq over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-42645HIGH An issue in FlashMQ v1.14.0 allows attackers to cause an assertion failure via sending a crafted retain message, leading to a Denial of Service (DoS). | Jul 29, 2025 | 7.5 | 25 | NO | NO |
CVE-2024-42644HIGH FlashMQ v1.14.0 was discovered to contain an assertion failure in the function PublishCopyFactory::getNewPublish, which occurs when the QoS value of the publish object is greater t | Jul 29, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-62723MEDIUM FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.23.2, any authenticated user can create sessions and have them collect QoS messages. When n | Oct 24, 2025 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flashmq.
Media articles that mention a CVE ID that affects a product developed by Flashmq — matched by CVE ID, not by vendor name.