{"id":"CVE-2026-95843","summary":"Moquette malformed shared subscriptions can crash command processing","details":"Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.subscribe parses a shared-subscription filter through SharedSubscriptionUtils.extractShareName before validating the complete $share/{shareName}/{topicFilter} structure. A remote client can send a filter such as $share/grp without a topic-filter portion, causing a StringIndexOutOfBoundsException while calculating the share name. The exception terminates command handling on the shared session event loop and can deny service to other client sessions assigned to that loop. This issue is fixed in version 0.18.1.","aliases":["CVE-2026-85724","CVE-2026-95842","CVE-2026-95844","CVE-2026-95845","CVE-2026-95846","CVE-2026-95847","CVE-2026-95848","GHSA-5f42-97gr-vfhq"],"modified":"2026-09-27T08:01:30.995780Z","published":"2026-09-23T16:29:44.588Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-20"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/95xxx/CVE-2026-95843.json"},"references":[{"type":"WEB","url":"https://github.com/moquette-io/moquette/releases/tag/v0.18.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/95xxx/CVE-2026-95843.json"},{"type":"ADVISORY","url":"https://github.com/moquette-io/moquette/security/advisories/GHSA-5f42-97gr-vfhq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-95843"},{"type":"FIX","url":"https://github.com/moquette-io/moquette/commit/affdc71fdba92dc020421678970ae70518fb6da2"},{"type":"FIX","url":"https://github.com/moquette-io/moquette/pull/962"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/moquette-io/moquette","events":[{"introduced":"0"},{"fixed":"e8ce83336acce69d8e9c11c98805217aa156a16b"},{"fixed":"affdc71fdba92dc020421678970ae70518fb6da2"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"0.18.1"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:moquette:moquette:*:*:*:*:*:*:*:*"}}],"versions":["v0.18.0","0.18.0","last_gradle","v0.12.1","v0.12","v0.11","second_try_with_osgi_giveup","last_with_maven","v0.10","before_sofia2","v0.9","v0.8","last_with_ringbuffer","0.7","last_osgi"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-95843.json","vanir_signatures_modified":"2026-09-27T08:01:30Z","vanir_signatures":[{"signature_type":"Line","signature_version":"v1","source":"https://github.com/moquette-io/moquette/commit/affdc71fdba92dc020421678970ae70518fb6da2","target":{"file":"broker/src/test/java/io/moquette/broker/SessionEventLoopTest.java"},"deprecated":false,"digest":{"line_hashes":["260478471734483761549100715465886470868","60415648911726053262337263363581505916","212963164542809097223158470117432098792","66930572998699971319340826652824315649","95833119695761673601431083465406292404","174457557961167344406769577226070698984"],"threshold":0.9},"id":"CVE-2026-95843-38db9523"},{"target":{"file":"broker/src/main/java/io/moquette/broker/PostOffice.java","function":"subscribeClientToTopics"},"deprecated":false,"digest":{"length":2405,"function_hash":"134349480296543909299472719321097315443"},"id":"CVE-2026-95843-5a133aeb","signature_type":"Function","signature_version":"v1","source":"https://github.com/moquette-io/moquette/commit/affdc71fdba92dc020421678970ae70518fb6da2"},{"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["125934402496039774032489400899577824671","97613260811307606878787548982365940575","194124313706569377730830380205618863064","98759703094230735429873617428752823834","151667620550621537510635487564784526737","298665657250269000325539426819647196805","6961804197908287411135667264258188116","115702242087409162551442075226758708597","73239519799422741324174551015351375855","111626495142943806698198271900118451859","106722594160222890831110186940622336431","242235614090897640158795429959330186798","136376459619982409254979200638312985417","328326150562565909947507184007524171995","175960658397598025555836414328727520262"]},"id":"CVE-2026-95843-67f4fadd","signature_type":"Line","signature_version":"v1","source":"https://github.com/moquette-io/moquette/commit/affdc71fdba92dc020421678970ae70518fb6da2","target":{"file":"broker/src/main/java/io/moquette/broker/PostOffice.java"}},{"deprecated":false,"digest":{"line_hashes":["146408937695327925013946960741496245001","35240469452939156180892302589480994893"],"threshold":0.9},"id":"CVE-2026-95843-ab438d47","signature_type":"Line","signature_version":"v1","source":"https://github.com/moquette-io/moquette/commit/affdc71fdba92dc020421678970ae70518fb6da2","target":{"file":"broker/src/main/java/io/moquette/broker/SharedSubscriptionUtils.java"}},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/moquette-io/moquette/commit/e8ce83336acce69d8e9c11c98805217aa156a16b","target":{"file":"broker/src/main/java/io/moquette/broker/Server.java"},"deprecated":false,"digest":{"line_hashes":["264460424198365981025294149882277014898","11410191927348774178838709852851310256","273802157253247414129958982189405529275","315296026132642631038163665576809441438"],"threshold":0.9},"id":"CVE-2026-95843-dd85d397"},{"deprecated":false,"digest":{"function_hash":"79921775663416493771587660209009728913","length":744},"id":"CVE-2026-95843-f22c9bdd","signature_type":"Function","signature_version":"v1","source":"https://github.com/moquette-io/moquette/commit/affdc71fdba92dc020421678970ae70518fb6da2","target":{"file":"broker/src/test/java/io/moquette/broker/SessionEventLoopTest.java","function":"givenACommandThatThrowsWhenProcessedThenTheSharedSessionLoopKeepsRunning"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}