PatchSiren cyber security CVE debrief
CVE-2026-95844 moquette-io CVE debrief
A remote client can publish or subscribe with a deeply nested topic to a Moquette MQTT broker, causing a StackOverflowError that disrupts session processing and can deny service to broker clients. This issue is fixed in version 0.18.1. The vulnerability allows an attacker to cause a denial of service by exploiting the recursive CTrie insertion and matching operations in Moquette. Defenders should assess exposure and prioritize upgrading to version 0.18.1 or later to prevent potential service disruption.
- Vendor
- moquette-io
- Product
- moquette
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-23
- Original CVE updated
- 2026-09-28
- Advisory published
- 2026-09-23
- Advisory updated
- 2026-09-28
Who should care
Defenders responsible for MQTT broker infrastructure, particularly those using Moquette, should assess exposure and prioritize upgrading to version 0.18.1 or later. This includes operators, platform administrators, vulnerability management teams, and security teams who need to verify and upgrade their Moquette MQTT brokers to prevent potential service disruption.
Why it matters
Defenders should prioritize verifying and upgrading Moquette MQTT broker to version 0.18.1 or later to prevent potential service disruption caused by deeply nested topic names and topic filters.
- Potential service disruption due to StackOverflowError
- Need to verify and upgrade to fixed version
- Possible impact on MQTT broker clients
Technical summary
Moquette MQTT broker versions prior to 0.18.1 do not limit the depth of topic names and topic filters, allowing a remote client to cause a StackOverflowError and disrupt session processing. The vulnerability can be exploited by publishing or subscribing with deeply nested topics, which can lead to a denial of service. Defenders should prioritize verifying and upgrading to Moquette version 0.18.1 or later to prevent potential service disruption caused by deeply nested topic names and topic filters. The vulnerability has a high CVSS score of 8.7, indicating a high severity.
Defensive priority
Defenders should prioritize verifying and upgrading to Moquette version 0.18.1 or later to prevent potential service disruption.
Recommended defensive actions
- Verify the Moquette version and upgrade to 0.18.1 or later
- Monitor for deeply nested topic names and topic filters
- Implement compensating controls to prevent service disruption
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, its impact, and the fixed version. The vulnerability is caused by the lack of depth limitation in topic names and topic filters in Moquette MQTT broker versions prior to 0.18.1. The CVE Program record and NVD detail page offer source-provided CVE metadata and official vulnerability assessment. Additional information can be found in the patch reference, release notes, and exploit, mitigation, and vendor advisory references.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-95844 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-95844
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-95844 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-95844
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/moquette-io/moquette/commit/ca17e0be19e86d5e291f4532dfdc94616c8e0049
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/moquette-io/moquette/releases/tag/v0.18.1
[email protected] - Release Notes
-
Source reference
Unverified legacy reference
URL: https://github.com/moquette-io/moquette/security/advisories/GHSA-5f42-97gr-vfhq
[email protected] - Exploit, Mitigation, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.