io.moquette:moquette-broker
Maven9 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting io.moquette:moquette-brokerpage 1 of 1
- CVE-2026-85058HIGHCVSS 7.5EG 7.5✓ Fixed in 0.18.12026-09-18
vulnerable: 0.15, 0.16, 0.17
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client-controlled Last Will message through publish2Subscribers without invoking the authorizator.canWrite check used by normal PUBLISH paths. …
- CVE-2026-85724CRITICALCVSS 9.6EG 9.6✓ Fixed in 0.18.12026-09-23
vulnerable: 0.15, 0.16, 0.17
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when pattern-based ACL rules are configured, AuthorizationsCollector.canDoOperation substitutes client ID and username values directly into rules containing %c or %u and then tre…
- CVE-2026-95842HIGHCVSS 8.7EG 8.7✓ Fixed in 0.18.12026-09-23
vulnerable: 0.15, 0.16, 0.17
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, SessionEventLoop.run catches only InterruptedException, and SessionEventLoopGroup does not restart a terminated loop. An MQTT command that raises an uncaught exception can termin…
- CVE-2026-95843HIGHCVSS 8.7EG 8.7✓ Fixed in 0.18.12026-09-23
vulnerable: 0.15, 0.16, 0.17
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.subscribe parses a shared-subscription filter through SharedSubscriptionUtils.extractShareName before validating the complete $share/{shareName}/{topicFilter} structur…
- CVE-2026-95844HIGHCVSS 8.7EG 8.7✓ Fixed in 0.18.12026-09-23
vulnerable: 0.15, 0.16, 0.17
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, Moquette does not limit the depth of topic names and topic filters before processing them through recursive CTrie insertion and matching operations. A remote client can publish o…
- CVE-2026-95845HIGHCVSS 8.7EG 8.7✓ Fixed in 0.18.12026-09-23
vulnerable: 0.15, 0.16, 0.17
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, the broker does not enforce a maximum length for pending per-session message queues. When a fast publisher sends messages to a slow subscriber whose in-flight window is full, que…
- CVE-2026-95846HIGHCVSS 8.7EG 8.7✓ Fixed in 0.18.12026-09-23
vulnerable: 0.15, 0.16, 0.17
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client's Last-Will message without applying the canWrite authorization and reserved-topic checks used for a normal PUBLISH. A client can config…
- CVE-2026-95847HIGHCVSS 8.8EG 8.8✓ Fixed in 0.18.12026-09-23
vulnerable: 0.15, 0.16, 0.17
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, H2PersistentQueue derives a session's message-map name as queue_ plus the client ID and its metadata-map name as queue_ plus the client ID plus _meta. A durable session whose cli…
- CVE-2026-95848CRITICALCVSS 9.3EG 9.3✓ Fixed in 0.18.12026-09-23
vulnerable: 0.15, 0.16, 0.17
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when a configured authenticator or authorizator class cannot be loaded, Server.initializeAuthenticator and Server.initializeAuthorizatorPolicy treat the failure as though no cust…
Check whether io.moquette:moquette-broker is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for io.moquette:moquette-broker CVEs against the assets you own.
Book a Demo →