Official source evidencegithub.comVersioned article
Official source article · github.com

Release Release 0.18.1 · moquette-io/moquette · GitHub

BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.

Read the official article ↗
Publishergithub.com
Article IDNo stable ID in source URL
Verified snapshot26 Sept 2026, 10:52 UTC
Linked CVEs8

Linked CVE reports

These are source relationships, not a claim that this article fixes every affected product or branch.

  • CVE-2026-95844Moquette deeply nested MQTT topics can cause stack exhaustion
  • CVE-2026-95846Moquette publishes Last-Will messages without enforcing write authorization
  • CVE-2026-85724Moquette pattern ACL wildcard injection allows cross-tenant authorization bypass
  • CVE-2026-95845Moquette unbounded per-session message queues allow memory exhaustion
  • CVE-2026-95848Moquette fails open when configured authentication or authorization classes cannot load
  • CVE-2026-95843Moquette malformed shared subscriptions can crash command processing
  • CVE-2026-95847Moquette client IDs can cause cross-session H2 durable-queue corruption
  • CVE-2026-95842Moquette uncaught MQTT command exceptions can terminate shared session event loops

Source and provenance

Original title: Release Release 0.18.1 · moquette-io/moquette · GitHub. Captured 26 Sept 2026, 10:52 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.

Open the publisher's current version ↗