CVE-2026-85442
nicheUnbounded buffer allocation DoS in MOOS core-moos (≤ 10.4.0)
CVE-2026-85442 is an unauthenticated denial-of-service flaw in MOOS core-moos through version 10.4.0, caused by failure to validate packet length declarations in CMOOSCommPkt::OnBytesWritten(). An attacker can send crafted wire packets declaring large lengths to the MOOS server, triggering unbounded buffer allocation and exhausting server memory. Successful attacks result in denial of service against the affected process (e.g., the MOOSDB communications server), with no confidentiality or integrity impact. Any deployment running core-moos 10.4.0 or earlier is affected, and the flaw is reachable pre-authentication, so even clients that have not logged in can trigger it. There is currently no known public proof-of-concept, no listing in CISA KEV, and a low (0.4%) 30-day exploitation probability per EPSS.
What to do: Upgrade to a fixed core-moos release as soon as the vendor publishes one (no fixed version is specified in the available data; monitor the MOOS project's advisories). Until then, restrict network access to MOOSDB and related MOOS communication ports to trusted hosts and networks via firewall rules, since the flaw is exploitable before authentication. Monitor server memory usage for abnormal growth from unauthenticated connections.
| MOOS project (open-source robotics middleware) core-moos (MOOS core communications library/server, incl. MOOSDB) | through 10.4.0 (all versions ≤ 10.4.0) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
MOOS core-moos through 10.4.0 fails to validate packet length declarations in CMOOSCommPkt::OnBytesWritten(), allowing unauthenticated attackers to trigger unbounded buffer allocation by sending crafted wire packets. Attackers can send packets with large declared lengths to exhaust server memory and cause denial of service before client authentication completes.
- Weakness
- CWE-789
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.