Official source evidenceGitHubGHSA-5F42-97GR-VFHQ
Official source article · GitHub

GHSA-5F42-97GR-VFHQ: Pattern-ACL wildcard injection (cross-tenant authorization bypass) plus a remote-unauthenticated DoS cluster, a Will-message authorization bypass, and a cross-session durable-corruption bug · Advisory · moquette-io/moquette · GitHub

BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.

Read the official article ↗
PublisherGitHub
Article IDGHSA-5F42-97GR-VFHQ
Verified snapshot26 Sept 2026, 10:52 UTC
Linked CVEs8

Linked CVE reports

These are source relationships, not a claim that this article fixes every affected product or branch.

  • CVE-2026-95844Moquette deeply nested MQTT topics can cause stack exhaustion
  • CVE-2026-95846Moquette publishes Last-Will messages without enforcing write authorization
  • CVE-2026-85724Moquette pattern ACL wildcard injection allows cross-tenant authorization bypass
  • CVE-2026-95845Moquette unbounded per-session message queues allow memory exhaustion
  • CVE-2026-95848Moquette fails open when configured authentication or authorization classes cannot load
  • CVE-2026-95843Moquette malformed shared subscriptions can crash command processing
  • CVE-2026-95847Moquette client IDs can cause cross-session H2 durable-queue corruption
  • CVE-2026-95842Moquette uncaught MQTT command exceptions can terminate shared session event loops

Source and provenance

Original title: Pattern-ACL wildcard injection (cross-tenant authorization bypass) plus a remote-unauthenticated DoS cluster, a Will-message authorization bypass, and a cross-session durable-corruption bug · Advisory · moquette-io/moquette · GitHub. Captured 26 Sept 2026, 10:52 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.

Open the publisher's current version ↗