moquette-io moquette

9 known vulnerabilities in moquette-io moquette, 2 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-95848 CVSS 9.3 critical Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when a configured authenticator or authorizator class cannot be loaded…
  • CVE-2026-95847 CVSS 8.8 high Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, H2PersistentQueue derives a session's message-map name as queue_ plus the…
  • CVE-2026-95846 CVSS 8.7 high Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client's Last-Will message without…
  • CVE-2026-95845 CVSS 8.7 high Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, the broker does not enforce a maximum length for pending per-session message…
  • CVE-2026-95844 CVSS 8.7 high Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, Moquette does not limit the depth of topic names and topic filters before…
  • CVE-2026-95843 CVSS 8.7 high Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.subscribe parses a shared-subscription filter through…
  • CVE-2026-95842 CVSS 8.7 high Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, SessionEventLoop.run catches only InterruptedException, and…
  • CVE-2026-85724 CVSS 9.6 critical Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when pattern-based ACL rules are configured…
  • CVE-2026-85058 CVSS 7.5 high Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client-controlled Last Will message…