Denial of Service Vulnerability in Moquette MQTT Broker
CVE-2026-95845

8.7HIGH

Key Information:

Status
Vendor
CVE Published:
23 September 2026

What is CVE-2026-95845?

The Moquette MQTT Broker, prior to version 0.18.1, contains a vulnerability where it fails to enforce a limit on the maximum length of pending per-session message queues. This oversight allows a scenario where rapid message publishing can lead to unbounded accumulation of queued messages in memory or persistent storage, particularly impacting slow subscribers with full in-flight windows. Remote clients can exploit this vulnerability to exhaust broker resources, resulting in denial of service conditions. Version 0.18.1 addresses and resolves this issue.

Affected Version(s)

moquette < 0.18.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.