BlackTreeCVE IntelligenceOfficial source evidenceGitHubGHSA-5F42-97GR-VFHQ
Official source article · GitHub
GHSA-5F42-97GR-VFHQ: Pattern-ACL wildcard injection (cross-tenant authorization bypass) plus a remote-unauthenticated DoS cluster, a Will-message authorization bypass, and a cross-session durable-corruption bug · Advisory · moquette-io/moquette · GitHub
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗PublisherGitHub
Article IDGHSA-5F42-97GR-VFHQ
Verified snapshot26 Sept 2026, 10:52 UTC
Linked CVEs8
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2026-95844Moquette deeply nested MQTT topics can cause stack exhaustion
- CVE-2026-95846Moquette publishes Last-Will messages without enforcing write authorization
- CVE-2026-85724Moquette pattern ACL wildcard injection allows cross-tenant authorization bypass
- CVE-2026-95845Moquette unbounded per-session message queues allow memory exhaustion
- CVE-2026-95848Moquette fails open when configured authentication or authorization classes cannot load
- CVE-2026-95843Moquette malformed shared subscriptions can crash command processing
- CVE-2026-95847Moquette client IDs can cause cross-session H2 durable-queue corruption
- CVE-2026-95842Moquette uncaught MQTT command exceptions can terminate shared session event loops
Source and provenance
Original title: Pattern-ACL wildcard injection (cross-tenant authorization bypass) plus a remote-unauthenticated DoS cluster, a Will-message authorization bypass, and a cross-session durable-corruption bug · Advisory · moquette-io/moquette · GitHub. Captured 26 Sept 2026, 10:52 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗