CVE-2026-85442

Source
https://cve.org/CVERecord?id=CVE-2026-85442
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85442.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-85442
Published
2026-09-03T22:38:32.543Z
Modified
2026-09-05T03:48:25.539071423Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
MOOS core-moos through 10.4.0 MOOSDB Denial of Service via Unbounded Packet Allocation
Details

MOOS core-moos through 10.4.0 fails to validate packet length declarations in CMOOSCommPkt::OnBytesWritten(), allowing unauthenticated attackers to trigger unbounded buffer allocation by sending crafted wire packets. Attackers can send packets with large declared lengths to exhaust server memory and cause denial of service before client authentication completes.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85442.json",
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-789"
    ]
}
References

Affected packages

Git / github.com/themoos/core-moos

Affected ranges

Type
GIT
Repo
https://github.com/themoos/core-moos
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "10.4.0"
        }
    ]
}

Affected versions

10.*
10.0.1-devel
10.0.2-devel
10.0.3-devel-candidate
Other
IvPCompatibility
PreProfilingmerge
v10.*
v10.0.4-alpha

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85442.json"