PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-95844 moquette-io CVE debrief

A remote client can publish or subscribe with a deeply nested topic to a Moquette MQTT broker, causing a StackOverflowError that disrupts session processing and can deny service to broker clients. This issue is fixed in version 0.18.1. The vulnerability allows an attacker to cause a denial of service by exploiting the recursive CTrie insertion and matching operations in Moquette. Defenders should assess exposure and prioritize upgrading to version 0.18.1 or later to prevent potential service disruption.

Vendor
moquette-io
Product
moquette
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-23
Original CVE updated
2026-09-28
Advisory published
2026-09-23
Advisory updated
2026-09-28

Who should care

Defenders responsible for MQTT broker infrastructure, particularly those using Moquette, should assess exposure and prioritize upgrading to version 0.18.1 or later. This includes operators, platform administrators, vulnerability management teams, and security teams who need to verify and upgrade their Moquette MQTT brokers to prevent potential service disruption.

Why it matters

Defenders should prioritize verifying and upgrading Moquette MQTT broker to version 0.18.1 or later to prevent potential service disruption caused by deeply nested topic names and topic filters.

  • Potential service disruption due to StackOverflowError
  • Need to verify and upgrade to fixed version
  • Possible impact on MQTT broker clients

Technical summary

Moquette MQTT broker versions prior to 0.18.1 do not limit the depth of topic names and topic filters, allowing a remote client to cause a StackOverflowError and disrupt session processing. The vulnerability can be exploited by publishing or subscribing with deeply nested topics, which can lead to a denial of service. Defenders should prioritize verifying and upgrading to Moquette version 0.18.1 or later to prevent potential service disruption caused by deeply nested topic names and topic filters. The vulnerability has a high CVSS score of 8.7, indicating a high severity.

Defensive priority

Defenders should prioritize verifying and upgrading to Moquette version 0.18.1 or later to prevent potential service disruption.

Recommended defensive actions

  • Verify the Moquette version and upgrade to 0.18.1 or later
  • Monitor for deeply nested topic names and topic filters
  • Implement compensating controls to prevent service disruption
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, its impact, and the fixed version. The vulnerability is caused by the lack of depth limitation in topic names and topic filters in Moquette MQTT broker versions prior to 0.18.1. The CVE Program record and NVD detail page offer source-provided CVE metadata and official vulnerability assessment. Additional information can be found in the patch reference, release notes, and exploit, mitigation, and vendor advisory references.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-95844 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-95844

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-95844 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-95844

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.