CVE-2026-95848
- EPSS 0.51%
- Veröffentlicht 23.09.2026 16:29:58
- Zuletzt bearbeitet 28.09.2026 15:23:06
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when a configured authenticator or authorizator class cannot be loaded, Server.initializeAuthenticator and Server.initializeAuthorizatorPolicy treat the failure as though no custom class wa...
CVE-2026-95847
- EPSS 0.41%
- Veröffentlicht 23.09.2026 16:29:56
- Zuletzt bearbeitet 28.09.2026 15:23:24
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, H2PersistentQueue derives a session's message-map name as queue_ plus the client ID and its metadata-map name as queue_ plus the client ID plus _meta. A durable session whose client ID ends...
CVE-2026-95846
- EPSS 0.29%
- Veröffentlicht 23.09.2026 16:29:54
- Zuletzt bearbeitet 25.09.2026 13:34:02
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client's Last-Will message without applying the canWrite authorization and reserved-topic checks used for a normal PUBLISH. A client can configure a Will ...
CVE-2026-95845
- EPSS 0.29%
- Veröffentlicht 23.09.2026 16:29:51
- Zuletzt bearbeitet 25.09.2026 13:34:37
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, the broker does not enforce a maximum length for pending per-session message queues. When a fast publisher sends messages to a slow subscriber whose in-flight window is full, queued message...
CVE-2026-95844
- EPSS 0.29%
- Veröffentlicht 23.09.2026 16:29:49
- Zuletzt bearbeitet 29.09.2026 02:16:55
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, Moquette does not limit the depth of topic names and topic filters before processing them through recursive CTrie insertion and matching operations. A remote client can publish or subscribe...
CVE-2026-95843
- EPSS 0.38%
- Veröffentlicht 23.09.2026 16:29:44
- Zuletzt bearbeitet 25.09.2026 13:34:44
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.subscribe parses a shared-subscription filter through SharedSubscriptionUtils.extractShareName before validating the complete $share/{shareName}/{topicFilter} structure. A remote...
CVE-2026-95842
- EPSS 0.38%
- Veröffentlicht 23.09.2026 16:29:41
- Zuletzt bearbeitet 25.09.2026 13:34:50
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, SessionEventLoop.run catches only InterruptedException, and SessionEventLoopGroup does not restart a terminated loop. An MQTT command that raises an uncaught exception can terminate an even...
CVE-2026-85724
- EPSS 0.26%
- Veröffentlicht 23.09.2026 16:29:36
- Zuletzt bearbeitet 25.09.2026 13:34:57
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when pattern-based ACL rules are configured, AuthorizationsCollector.canDoOperation substitutes client ID and username values directly into rules containing %c or %u and then treats the res...