Denial of Service Vulnerability in Moquette MQTT Broker
CVE-2026-95845
8.7HIGH
What is CVE-2026-95845?
The Moquette MQTT Broker, prior to version 0.18.1, contains a vulnerability where it fails to enforce a limit on the maximum length of pending per-session message queues. This oversight allows a scenario where rapid message publishing can lead to unbounded accumulation of queued messages in memory or persistent storage, particularly impacting slow subscribers with full in-flight windows. Remote clients can exploit this vulnerability to exhaust broker resources, resulting in denial of service conditions. Version 0.18.1 addresses and resolves this issue.
Affected Version(s)
moquette < 0.18.1
