Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, the broker does not enforce a maximum length for pending per-session message queues. When a fast publisher sends messages to a slow subscriber whose in-flight window is full, queued messages can accu
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| moquette-io | moquette | < 0.18.1 |
affected |
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| moquette-io | moquette | < 0.18.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85724 | 9.6 CRITICAL | Moquette pattern ACL wildcard injection allows cross-tenant authorization bypass |
| CVE-2026-95848 | 9.3 CRITICAL | Moquette fails open when configured authentication or authorization classes cannot load |
| CVE-2026-95847 | 8.8 HIGH | Moquette client IDs can cause cross-session H2 durable-queue corruption |
| CVE-2026-95846 | 8.7 HIGH | Moquette publishes Last-Will messages without enforcing write authorization |
| CVE-2026-95843 | 8.7 HIGH | Moquette malformed shared subscriptions can crash command processing |
| CVE-2026-95842 | 8.7 HIGH | Moquette uncaught MQTT command exceptions can terminate shared session event loops |
| CVE-2026-95844 | 8.7 HIGH | Moquette deeply nested MQTT topics can cause stack exhaustion |
No comments yet