RMQTT Broker 0.4.0 is vulnerable to Denial of Service (DoS) due to improper session resource management. An attacker can exhaust system memory and crash the daemon by establishing and maintaining a vast number of long-lived malicious publish/subscribe sessions.
https://github.com/rmqtt/rmqtt/releases/tag/0.4.0
https://gist.github.com/pengwGit/d8410afeb0d5d11ab79f596a32178c2e