PT-2026-97395 · Moquette · Moquette

·

CVE-2026-95844

·

Published

2026-09-23

·

Updated

2026-09-29

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Moquette versions prior to 0.18.1
Description Moquette does not limit the depth of topic names and topic filters before processing them through recursive CTrie insertion and matching operations. A remote client can publish or subscribe using a deeply nested topic, triggering a StackOverflowError—a runtime error that occurs when the application's call stack exceeds its allocated limit—which disrupts session processing and results in a denial of service for broker clients.
Recommendations Update to version 0.18.1.

Exploit

Fix

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-95844
GHSA-5F42-97GR-VFHQ

Affected Products

Moquette