CVE-2026-95845
7.5 HIGHpublic exploit availablePublished 2026-09-23 · Updated 2026-09-25
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, the broker does not enforce a maximum length for pending per-session message queues. When a fast publisher sends messages to a slow subscriber whose in-flight window is full, queued messages can accumulate without bound in memory or persistent storage. Remote clients can use this condition to exhaust broker resources and cause a denial of service. This issue is fixed in version 0.18.1.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-770
Vendors
moquette
Products
moquette
Public exploit & PoC references
- https://github.com/moquette-io/moquette/commit/2482cadfba44e615be704b892009a57ce06a1aba[Patch]
- https://github.com/moquette-io/moquette/releases/tag/v0.18.1[Release Notes]
- https://github.com/moquette-io/moquette/security/advisories/GHSA-5f42-97gr-vfhq[Exploit, Mitigation, Vendor Advisory]
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2025-12767
- MEDIUMCVE-2026-100600PoC
- LOWCVE-2026-100649PoC
- HIGHCVE-2026-100660PoC
- LOWCVE-2026-101333
- UNSCOREDCVE-2026-101911PoC
- MEDIUMCVE-2026-101917PoC
- MEDIUMCVE-2026-10832
Related by shared AI tags and CWE weakness class. Browse the full archive.