{"id":"CVE-2025-62723","summary":"FlashMQ does not release memory of queued QoS messages","details":"FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.23.2, any authenticated user can create sessions and have them collect QoS messages. When not sent to a client, these are then not released upon (eventual) session expiration. Version 1.23.2 fixes the issue.","aliases":["GHSA-7mhp-22q4-r6vv"],"modified":"2026-08-12T15:14:28.398731Z","published":"2025-10-24T20:16:34.047Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/62xxx/CVE-2025-62723.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-772"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/62xxx/CVE-2025-62723.json"},{"type":"ADVISORY","url":"https://github.com/halfgaar/FlashMQ/security/advisories/GHSA-7mhp-22q4-r6vv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62723"},{"type":"REPORT","url":"https://github.com/halfgaar/FlashMQ/issues/154"},{"type":"FIX","url":"https://github.com/halfgaar/FlashMQ/commit/e86c49360ef4387440c97f591770cdb9284b4ee9"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/halfgaar/flashmq","events":[{"introduced":"0"},{"fixed":"d7df69c6e4cf9f9d6cd0e6b241b2e610f7cfc5fa"},{"fixed":"e86c49360ef4387440c97f591770cdb9284b4ee9"}],"database_specific":{"cpe":"cpe:2.3:a:flashmq:flashmq:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.23.2"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v1.23.1","v1.23.0","v1.22.0","v1.21.1","v1.21.0","v1.20.0","v1.19.0","v1.18.2","v1.18.1","v1.18.0","v1.17.2","v1.17.1","v1.17.0","v1.16.0","v1.15.4","v1.15.3","v1.15.2","v1.15.1","v1.15.0","v1.14.0","v1.13.1","v1.13.0","v1.12.1","v1.12.0","v1.11.0","v1.10.0","v1.9.1","v1.9.0","v1.8.4","v1.8.3","v1.8.2","v1.8.1","v1.8.0","v1.7.11","v1.7.10","v1.7.9","v1.7.8","v1.7.7","v1.7.6","v1.7.5","v1.7.4","v1.7.3","v1.7.2","v1.7.1","v1.7.0","v1.6.9","v1.6.8","v1.6.7","v1.6.6","v1.6.5","v1.6.4","v1.6.3","v1.6.2","v1.6.1","v1.6.0","v1.5.0","v1.4.5","v1.4.4","v1.4.3","v1.4.2","v1.4.1","v1.4.0","v1.3.1","v1.3.0","v1.2.1","v1.2.0","v1.1.0","v1.0.2","v1.0.1","v1.0.0","v0.13.1","v0.13.0","v0.12.1","v0.12.0","v0.11.9","v0.11.8","v0.11.7","v0.11.6","v0.11.5","v0.11.4","v0.11.3","v0.11.2","v0.11.1","v0.11.0","v0.10.1","v0.10.0","v0.9.9","v0.9.8","v0.9.7","v0.9.6","v0.9.5","v0.9.4","v0.9.3","v0.9.2","v0.9.1","v0.9.0","v0.8.1","v0.8.0","v0.7.1","v0.7.0","v0.6.3","v0.6.1","v0.6.0","v0.5.2","v0.5.1","v0.5.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-62723.json","vanir_signatures_modified":"2026-08-12T15:14:28Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/halfgaar/flashmq/commit/e86c49360ef4387440c97f591770cdb9284b4ee9","target":{"file":"qospacketqueue.cpp"},"deprecated":false,"digest":{"line_hashes":["140880744831599421164209095601313598851","293201533805515353543667372787349735304","286774563364948002628709278292298635090","299577384475013199334768788833787286869","91942813742935958485154992288428320791","120572350863590179600854038091542045458","136747871164285568645097398662490087707","168745381454669412706210456862198854579","260408427607833798626240264891447042862","307635325545961003772126074148755640217","89782838532029536761195789555886885732"],"threshold":0.9},"id":"CVE-2025-62723-5697e16d","signature_type":"Line"},{"deprecated":false,"digest":{"line_hashes":["271150014258681858475731030423252566958","256072799936919173655408503622140235920","330854773736132367153740918396621990181","153497775808203472934588052288343682366","176752241848744060994066246192137626171","290642285860598613313313161976050746549","336991049817550033182108469843364704548","58501498779111602985239004806103448860"],"threshold":0.9},"id":"CVE-2025-62723-6ffc8c4f","signature_type":"Line","signature_version":"v1","source":"https://github.com/halfgaar/flashmq/commit/e86c49360ef4387440c97f591770cdb9284b4ee9","target":{"file":"session.cpp"}},{"source":"https://github.com/halfgaar/flashmq/commit/e86c49360ef4387440c97f591770cdb9284b4ee9","target":{"file":"session.cpp","function":"Session::sendAllPendingQosData"},"deprecated":false,"digest":{"function_hash":"258411889830633429774713219641831641385","length":1723},"id":"CVE-2025-62723-85844b1b","signature_type":"Function","signature_version":"v1"},{"target":{"file":"qospacketqueue.h"},"deprecated":false,"digest":{"line_hashes":["181713935765820381246065127938567605973","70647802841101245854768500364207548622","242105203335683767689349706827003564347","107505130135611952690909865408638006773","218401919231566395665526837122329724721","191579165040173255855665114071802799669"],"threshold":0.9},"id":"CVE-2025-62723-9d9bdb0c","signature_type":"Line","signature_version":"v1","source":"https://github.com/halfgaar/flashmq/commit/e86c49360ef4387440c97f591770cdb9284b4ee9"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/halfgaar/flashmq/commit/e86c49360ef4387440c97f591770cdb9284b4ee9","target":{"file":"sessionsandsubscriptionsdb.cpp"},"deprecated":false,"digest":{"line_hashes":["135939606549860017972892984959953556652","158779470378015547488432048125859814650","30095610035722006964456639710544462191","82805202897635646380588049430590623768"],"threshold":0.9},"id":"CVE-2025-62723-ef60bf1f"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"}]}