High severityNVD Advisory· Published Sep 23, 2026· Updated Sep 23, 2026
CVE-2026-95845
CVE-2026-95845
Description
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, the broker does not enforce a maximum length for pending per-session message queues. When a fast publisher sends messages to a slow subscriber whose in-flight window is full, queued messages can accumulate without bound in memory or persistent storage. Remote clients can use this condition to exhaust broker resources and cause a denial of service. This issue is fixed in version 0.18.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <0.18.1
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.