High severityNVD Advisory· Published Sep 23, 2026· Updated Sep 23, 2026
CVE-2026-95844
CVE-2026-95844
Description
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, Moquette does not limit the depth of topic names and topic filters before processing them through recursive CTrie insertion and matching operations. A remote client can publish or subscribe with a deeply nested topic, causing a StackOverflowError that disrupts session processing and can deny service to broker clients. This issue is fixed in version 0.18.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <0.18.1
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.