MOOS core-moos through 10.4.0 fails to validate that serialized string lengths are non-negative in CMOOSMsg::operator>>. Unauthenticated attackers can send a crafted message with a negative length value to the MOOSDB port, causing an unhandled exception that terminates the database process.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 03 Sep 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MOOS core-moos through 10.4.0 fails to validate that serialized string lengths are non-negative in CMOOSMsg::operator>>. Unauthenticated attackers can send a crafted message with a negative length value to the MOOSDB port, causing an unhandled exception that terminates the database process. | |
| Title | MOOS core-moos through 10.4.0 MOOSDB Denial of Service via Negative Serialized String Length | |
| Weaknesses | CWE-195 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-03T22:38:31.884Z
Reserved: 2026-09-03T19:50:58.148Z
Link: CVE-2026-85441
No data.
Status : Received
Published: 2026-09-03T23:17:23.740
Modified: 2026-09-03T23:17:23.740
Link: CVE-2026-85441
No data.
OpenCVE Enrichment
Updated: 2026-09-04T00:00:09Z
Weaknesses