Security: moquette-io/moquette
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Moquette: repeated CONNECT on one connection leaks permanent zombie sessions -> unbounded RAM/disk DoS, bypasses persistent_client_expiration (MQTTConnection.java:113)GHSA-wcrr-jh84-fchg published
Aug 16, 2026 by andselModerate -
Moquette retains unbounded slow-subscriber session queue entries when PUBACKs are withheldGHSA-7f46-5777-wf44 published
Aug 1, 2026 by andselModerate -
Pattern-ACL wildcard injection (cross-tenant authorization bypass) plus a remote-unauthenticated DoS cluster, a Will-message authorization bypass, and a cross-session durable-corruption bugGHSA-5f42-97gr-vfhq published
Aug 1, 2026 by andselCritical -
Missing Authorization in io.moquette:moquette-brokerGHSA-9jjc-fw8x-fmwx published
Aug 1, 2026 by andselHigh -
Uncontrolled Recursion in Subscription Tree (CTrie) Leads to Denial of Service via StackOverflowErrorGHSA-vq7g-2g8v-w65q published
Aug 1, 2026 by andselHigh
Learn more about advisories related to moquette-io/moquette in the GitHub Advisory Database