OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-95845

HIGH · CVSS 7.5 EPSS 0.36% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The Moquette MQTT broker prior to version 0.18.1 is vulnerable due to the lack of enforced limits on pending message queues, allowing remote clients to exploit this by overwhelming the broker with messages. This can lead to resource exhaustion, resulting in a denial of service for legitimate users. Organizations using this broker should prioritize upgrading to version 0.18.1 to mitigate the risk of service disruption.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-95845
Severity
HIGH
CVSS
7.5
EPSS
0.36%
Java

Original NVD Description

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, the broker does not enforce a maximum length for pending per-session message queues. When a fast publisher sends messages to a slow subscriber whose in-flight window is full, queued messages can accumulate without bound in memory or persistent storage. Remote clients can use this condition to exhaust broker resources and cause a denial of service. This issue is fixed in version 0.18.1.

Related CVEs

Other vulnerabilities affecting the same vendor(s)