PatchSiren cyber security CVE debrief
CVE-2026-95847 moquette-io CVE debrief
CVE-2026-95847 is a high-severity vulnerability in Moquette, a lightweight Java MQTT broker. The issue arises from how Moquette handles durable sessions, specifically when a client ID ends in '_meta', leading to a collision between the message map and metadata map. This collision can corrupt queue data, cause message loss or misdelivery, and potentially expose queued content across sessions. The vulnerability is fixed in version 0.18.1.
- Vendor
- moquette-io
- Product
- moquette
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-23
- Original CVE updated
- 2026-09-28
- Advisory published
- 2026-09-23
- Advisory updated
- 2026-09-28
Who should care
Defenders responsible for MQTT brokers and applications using Moquette should assess their exposure and prioritize updating to version 0.18.1 or later to prevent potential data corruption and message exposure.
Why it matters
CVE-2026-95847 is a high-severity vulnerability in Moquette that can lead to data corruption, message loss, and potential exposure of queued content. Defenders should prioritize updating to version 0.18.1 or later and assess their exposure.
- Potential data corruption in Moquette queues
- Message loss or misdelivery due to map collisions
- Exposure of queued content across sessions
- Verification of Moquette version and inventory checks required
Technical summary
The vulnerability in Moquette arises from the way it handles durable sessions. When a client ID ends in '_meta', it can cause a collision between the message map and metadata map, leading to data corruption and potential exposure of queued content. This issue is addressed in version 0.18.1. Defenders should prioritize updating Moquette to version 0.18.1 or later to prevent potential data corruption and message exposure. MQTT brokers and applications using Moquette should assess their exposure and verify the version in use, focusing on identifying and mitigating potential impacts on queue data integrity and message delivery.
Defensive priority
Defenders should prioritize updating Moquette to version 0.18.1 or later to prevent potential data corruption and message exposure. MQTT brokers and applications using Moquette should assess their exposure and verify the version in use.
Recommended defensive actions
- Update Moquette to version 0.18.1 or later
- Assess exposure of MQTT brokers and applications using Moquette
- Verify the version of Moquette in use
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, its impact, and the fix in version 0.18.1. GitHub references offer additional context on the patches and release notes. Defenders should verify the Moquette version in use, assess exposure, and prioritize updating to version 0.18.1 or later. Evidence from the CVE Program and NVD detail page supports this guidance, emphasizing the need for immediate attention to prevent potential data corruption and message exposure.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-95847 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-95847
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-95847 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-95847
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/moquette-io/moquette/commit/72d6c8257191d2e4b2e3aa11ab25fd09f88c6cb7
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/moquette-io/moquette/pull/964
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/moquette-io/moquette/releases/tag/v0.18.1
[email protected] - Release Notes
-
Source reference
Unverified legacy reference
URL: https://github.com/moquette-io/moquette/security/advisories/GHSA-5f42-97gr-vfhq
[email protected] - Exploit, Mitigation, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.