Aias00 opened a new issue, #6746:
URL: https://github.com/apache/shenyu/issues/6746

   - severity: Medium
   - files: 
`shenyu-protocol/shenyu-protocol-mqtt/src/main/java/org/apache/shenyu/protocol/mqtt/repositories/SubscribeRepository.java:43-48,56-62,90-92`
   - description: `add(Channel, List<MqttTopicSubscription>)` runs in 
`CompletableFuture.runAsync` + `parallelStream`, calls `get(topic)` which 
returns a fresh `new CopyOnWriteArrayList<>()` via `getOrDefault` for an absent 
topic (a transient list not inserted into the map), `channels.add(channel)`, 
then `put`. Two concurrent subscribers to a new topic each get an empty list, 
add themselves, and `put` — last write wins, first subscriber silently dropped.
   - impact: Subscribers silently lost under concurrent subscription to the 
same topic; messages not delivered to all.
   - suggested_fix: Use `computeIfAbsent` to obtain the canonical list and 
atomically add.
   - confidence: High
   - related_existing: none
   
   ---
   _Identified during the 2026-08-02 deep re-scan; full list in 
[`docs/scan2-2026-08-02/06-medium-tiers.md`](docs/scan2-2026-08-02/06-medium-tiers.md)._


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to