Denial of Service in Moquette MQTT Broker Affects Remote Client Functionality
CVE-2026-95844
8.7HIGH
What is CVE-2026-95844?
The Moquette MQTT Broker, prior to version 0.18.1, is vulnerable due to the lack of limits on the depth of topic names and filters during processing. A remote attacker could exploit this by publishing or subscribing with overly nested topics, leading to a StackOverflowError. This error interrupts session handling and could result in service disruption for legitimate users of the broker. The vulnerability has been remediated in version 0.18.1, making it essential for users to update to maintain service integrity.
Affected Version(s)
moquette < 0.18.1
