CVE-2026-85450

Summary

MOOS core-moos through 10.4.0 contains a denial of service vulnerability in the MOOSDB HTTP server that creates unbounded connections and threads without limits. Attackers can open many connections and send endless header data to exhaust server threads and memory, causing service unavailability.

Affected Software

VendorProductVersion RangeStatus
themooscore-moos0 <= 10.4.0affected

Weaknesses

  • CWE-770: Allocation of Resources Without Limits or Throttling

References