{"id":"CVE-2026-95845","summary":"Moquette unbounded per-session message queues allow memory exhaustion","details":"Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, the broker does not enforce a maximum length for pending per-session message queues. When a fast publisher sends messages to a slow subscriber whose in-flight window is full, queued messages can accumulate without bound in memory or persistent storage. Remote clients can use this condition to exhaust broker resources and cause a denial of service. This issue is fixed in version 0.18.1.","aliases":["CVE-2026-85724","CVE-2026-95842","CVE-2026-95843","CVE-2026-95844","CVE-2026-95846","CVE-2026-95847","CVE-2026-95848","GHSA-5f42-97gr-vfhq"],"modified":"2026-09-24T14:06:14.213224Z","published":"2026-09-23T16:29:51.402Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-770"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/95xxx/CVE-2026-95845.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/95xxx/CVE-2026-95845.json"},{"type":"FIX","url":"https://github.com/moquette-io/moquette/commit/2482cadfba44e615be704b892009a57ce06a1aba"},{"type":"WEB","url":"https://github.com/moquette-io/moquette/releases/tag/v0.18.1"},{"type":"ADVISORY","url":"https://github.com/moquette-io/moquette/security/advisories/GHSA-5f42-97gr-vfhq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-95845"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/moquette-io/moquette","events":[{"introduced":"0"},{"fixed":"e8ce83336acce69d8e9c11c98805217aa156a16b"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"0.18.1"}],"source":"AFFECTED_FIELD"}}],"versions":["v0.18.0","0.18.0","last_gradle","v0.12.1","v0.12","v0.11","second_try_with_osgi_giveup","last_with_maven","v0.10","before_sofia2","v0.9","v0.8","last_with_ringbuffer","0.7","last_osgi"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-95845.json","vanir_signatures_modified":"2026-09-24T14:06:14Z","vanir_signatures":[{"signature_type":"Line","signature_version":"v1","source":"https://github.com/moquette-io/moquette/commit/e8ce83336acce69d8e9c11c98805217aa156a16b","target":{"file":"broker/src/main/java/io/moquette/broker/Server.java"},"deprecated":false,"digest":{"line_hashes":["264460424198365981025294149882277014898","11410191927348774178838709852851310256","273802157253247414129958982189405529275","315296026132642631038163665576809441438"],"threshold":0.9},"id":"CVE-2026-95845-dd85d397"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}