{"id":"CVE-2026-95844","summary":"Moquette deeply nested MQTT topics can cause stack exhaustion","details":"Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, Moquette does not limit the depth of topic names and topic filters before processing them through recursive CTrie insertion and matching operations. A remote client can publish or subscribe with a deeply nested topic, causing a StackOverflowError that disrupts session processing and can deny service to broker clients. This issue is fixed in version 0.18.1.","aliases":["CVE-2026-85724","CVE-2026-95842","CVE-2026-95843","CVE-2026-95845","CVE-2026-95846","CVE-2026-95847","CVE-2026-95848","GHSA-5f42-97gr-vfhq"],"modified":"2026-09-25T08:07:07.054973Z","published":"2026-09-23T16:29:49.416Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-674"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/95xxx/CVE-2026-95844.json"},"references":[{"type":"WEB","url":"https://github.com/moquette-io/moquette/releases/tag/v0.18.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/95xxx/CVE-2026-95844.json"},{"type":"ADVISORY","url":"https://github.com/moquette-io/moquette/security/advisories/GHSA-5f42-97gr-vfhq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-95844"},{"type":"FIX","url":"https://github.com/moquette-io/moquette/commit/ca17e0be19e86d5e291f4532dfdc94616c8e0049"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/moquette-io/moquette","events":[{"introduced":"0"},{"fixed":"ca17e0be19e86d5e291f4532dfdc94616c8e0049"},{"fixed":"e8ce83336acce69d8e9c11c98805217aa156a16b"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"0.18.1"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v0.18.0","0.18.0","last_gradle","v0.12.1","v0.12","v0.11","second_try_with_osgi_giveup","last_with_maven","v0.10","before_sofia2","v0.9","v0.8","last_with_ringbuffer","0.7","last_osgi"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-95844.json","vanir_signatures_modified":"2026-09-25T08:07:07Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/moquette-io/moquette/commit/ca17e0be19e86d5e291f4532dfdc94616c8e0049","target":{"file":"broker/src/main/java/io/moquette/broker/subscriptions/CTrieSubscriptionDirectory.java","function":"add"},"deprecated":false,"digest":{"function_hash":"201591643342668298356752466913396961474","length":145},"id":"CVE-2026-95844-2b76889b","signature_type":"Function"},{"deprecated":false,"digest":{"line_hashes":["15339115696184662820910445885183031801","175247161545591798358870256959106166937","108717040719820457203411401021437351449","246268873576931606520343665142049592302","99159720380727079807578155001541389939","160824523760939090856003886257695987849"],"threshold":0.9},"id":"CVE-2026-95844-4114c6cd","signature_type":"Line","signature_version":"v1","source":"https://github.com/moquette-io/moquette/commit/ca17e0be19e86d5e291f4532dfdc94616c8e0049","target":{"file":"broker/src/main/java/io/moquette/broker/subscriptions/CTrie.java"}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/moquette-io/moquette/commit/ca17e0be19e86d5e291f4532dfdc94616c8e0049","target":{"file":"broker/src/main/java/io/moquette/broker/subscriptions/CTrie.java","function":"addToTree"},"deprecated":false,"digest":{"function_hash":"224443298933801707176232087917321461621","length":182},"id":"CVE-2026-95844-4c8641a4"},{"digest":{"threshold":0.9,"line_hashes":["141509072151506030695897486837733089590","303084007873226834877968351131837079789","324850687627758246828696551661799702268","254432595748596375790264329323134777822","310640531364842450078214099801281419770","150402725774214272510762363215826748355","6754594743559529307321015896987856840","32097691332907117206191960035684309787","16489679122410066886748171705826809617","158943096766114732093835236001789680861","317738492324563571849698991588799266467","312961000447935311120806466442838340665"]},"id":"CVE-2026-95844-533eead9","signature_type":"Line","signature_version":"v1","source":"https://github.com/moquette-io/moquette/commit/ca17e0be19e86d5e291f4532dfdc94616c8e0049","target":{"file":"broker/src/test/java/io/moquette/integration/PublishTest.java"},"deprecated":false},{"digest":{"line_hashes":["241517880470991870039756577146353928545","231074171125330367174771897500960571506","152321101354999755213964417607137134144","237237765105319684642045323999066980818"],"threshold":0.9},"id":"CVE-2026-95844-5b55f728","signature_type":"Line","signature_version":"v1","source":"https://github.com/moquette-io/moquette/commit/ca17e0be19e86d5e291f4532dfdc94616c8e0049","target":{"file":"broker/src/test/java/io/moquette/integration/mqtt5/AbstractServerIntegrationTest.java"},"deprecated":false},{"digest":{"line_hashes":["94979580496469434399416510512097488213","104868421946502236748175281127230093303","301404207672823252159331177736252834397","104383482731511982109451399561525465661"],"threshold":0.9},"id":"CVE-2026-95844-6f3f4e6d","signature_type":"Line","signature_version":"v1","source":"https://github.com/moquette-io/moquette/commit/ca17e0be19e86d5e291f4532dfdc94616c8e0049","target":{"file":"broker/src/main/java/io/moquette/BrokerConstants.java"},"deprecated":false},{"deprecated":false,"digest":{"function_hash":"9583661072935533481008253022213537707","length":516},"id":"CVE-2026-95844-9accdecb","signature_type":"Function","signature_version":"v1","source":"https://github.com/moquette-io/moquette/commit/ca17e0be19e86d5e291f4532dfdc94616c8e0049","target":{"file":"broker/src/main/java/io/moquette/broker/MQTTConnection.java","function":"processSubscribe"}},{"source":"https://github.com/moquette-io/moquette/commit/ca17e0be19e86d5e291f4532dfdc94616c8e0049","target":{"file":"broker/src/main/java/io/moquette/broker/MQTTConnection.java"},"deprecated":false,"digest":{"line_hashes":["4334178915854665844163088842878224506","260802962657757270918001095533806000563","117503045512709299914278598442555706501","31430281227117752874523953487497352525","38043879429490085093728869391716634184","282860472553128524545731658897564325255","72729412325842961831972651781172021381","76629987900634430376853636074720887066","135811861804839434732923757383379463592","308981989691946813652343704174425628580","321408865624781661714511570624318097030"],"threshold":0.9},"id":"CVE-2026-95844-9d9fe73e","signature_type":"Line","signature_version":"v1"},{"source":"https://github.com/moquette-io/moquette/commit/ca17e0be19e86d5e291f4532dfdc94616c8e0049","target":{"file":"broker/src/main/java/io/moquette/broker/subscriptions/CTrieSubscriptionDirectory.java","function":"init"},"deprecated":false,"digest":{"function_hash":"295705922836210006122360946702919780207","length":925},"id":"CVE-2026-95844-ac963b3c","signature_type":"Function","signature_version":"v1"},{"target":{"file":"broker/src/main/java/io/moquette/broker/subscriptions/CTrieSubscriptionDirectory.java","function":"add"},"deprecated":false,"digest":{"function_hash":"27238272702242033542996418725915890673","length":167},"id":"CVE-2026-95844-c5d3c42e","signature_type":"Function","signature_version":"v1","source":"https://github.com/moquette-io/moquette/commit/ca17e0be19e86d5e291f4532dfdc94616c8e0049"},{"digest":{"line_hashes":["264460424198365981025294149882277014898","11410191927348774178838709852851310256","273802157253247414129958982189405529275","315296026132642631038163665576809441438"],"threshold":0.9},"id":"CVE-2026-95844-dd85d397","signature_type":"Line","signature_version":"v1","source":"https://github.com/moquette-io/moquette/commit/e8ce83336acce69d8e9c11c98805217aa156a16b","target":{"file":"broker/src/main/java/io/moquette/broker/Server.java"},"deprecated":false},{"deprecated":false,"digest":{"line_hashes":["72677612426343428545204163904098726425","336979032457439812832060690559905230220","202615652329212212884631395771464405564","195877906768706673956035275612166034866","221436665488405065565815966159989824626","64082758867400879641585847486021492049","104521991681382050556722268375598057391","308770628994811630993027263398502411437","223072872274386292976395364472917503014","253881305926805937865375085839546781038","149755049273585797300272865678932440040","2871802532957240020414354426541134622","53482570082244736626195703025404091598","56677016991700366174589889043853481816","332744730198300464804741451501940744457","161626340458668137088347200616855138186","339407849045578461311524798658431002823","21659987249486939808623485332449219067"],"threshold":0.9},"id":"CVE-2026-95844-eec65a29","signature_type":"Line","signature_version":"v1","source":"https://github.com/moquette-io/moquette/commit/ca17e0be19e86d5e291f4532dfdc94616c8e0049","target":{"file":"broker/src/main/java/io/moquette/broker/subscriptions/CTrieSubscriptionDirectory.java"}},{"target":{"file":"broker/src/test/java/io/moquette/broker/subscriptions/CTrieSubscriptionDirectoryMatchingTest.java"},"deprecated":false,"digest":{"line_hashes":["70542175746939526815327874596639147136","219258057984306585479309240010911467575","133009495568284653229706800329766309121","133335324900233714383713213895005855817","15341332327444658451293905680642892122"],"threshold":0.9},"id":"CVE-2026-95844-f4a442c4","signature_type":"Line","signature_version":"v1","source":"https://github.com/moquette-io/moquette/commit/ca17e0be19e86d5e291f4532dfdc94616c8e0049"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/moquette-io/moquette/commit/ca17e0be19e86d5e291f4532dfdc94616c8e0049","target":{"file":"broker/src/main/java/io/moquette/broker/MQTTConnection.java","function":"processPublish"},"deprecated":false,"digest":{"length":3443,"function_hash":"270993343717710531729162086846919331478"},"id":"CVE-2026-95844-f8cd772d"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}