No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 23 Sep 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Moquette-io
Moquette-io moquette |
|
| Vendors & Products |
Moquette-io
Moquette-io moquette |
Wed, 23 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 23 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, H2PersistentQueue derives a session's message-map name as queue_ plus the client ID and its metadata-map name as queue_ plus the client ID plus _meta. A durable session whose client ID ends in _meta can therefore make its message map collide with another client's metadata map. The colliding sessions read and write the same H2 MVStore map with incompatible value types, which can corrupt queue head and tail data and cause message loss, misdelivery, failed queue reloads, or exposure of queued content across sessions. This issue is fixed in version 0.18.1. | |
| Title | Moquette client IDs can cause cross-session H2 durable-queue corruption | |
| Weaknesses | CWE-99 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-23T16:50:25.152Z
Reserved: 2026-09-22T16:39:45.794Z
Link: CVE-2026-95847
Updated: 2026-09-23T16:50:18.677Z
Status : Awaiting Analysis
Published: 2026-09-23T17:17:21.780
Modified: 2026-09-23T18:12:04.247
Link: CVE-2026-95847
No data.
OpenCVE Enrichment
Updated: 2026-09-23T19:00:07Z