Moquette · Moquette · CVE-2026-95847
**Name of the Vulnerable Software and Affected Versions**
Moquette versions prior to 0.18.1
**Description**
In the `H2PersistentQueue` component, session message-map names are derived using the prefix `queue ` followed by the client ID, while metadata-map names use `queue `, the client ID, and the suffix ` meta`. If a durable session uses a client ID that ends with ` meta`, its message map can collide with the metadata map of another client. This collision causes sessions to read and write to the same H2 MVStore map using incompatible value types, potentially leading to corrupted queue head and tail data, message loss, misdelivery, failed queue reloads, or the exposure of queued content between sessions.
**Recommendations**
Update to version 0.18.1.