CVE-2026-85450
Received Received - Intake

MOOS core-moos HTTP Server Denial of Service

Vulnerability report for CVE-2026-85450, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-03

Last updated on: 2026-09-03

Assigner: VulnCheck

Description

MOOS core-moos through 10.4.0 contains a denial of service vulnerability in the MOOSDB HTTP server that creates unbounded connections and threads without limits. Attackers can open many connections and send endless header data to exhaust server threads and memory, causing service unavailability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-03
Last Modified
2026-09-03
Generated
2026-09-04
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
moos core-moos to 10.4.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

MOOS core-moos through version 10.4.0 has a denial of service vulnerability in its HTTP server component. The issue allows attackers to create an excessive number of connections and threads by sending endless header data. This exhausts server resources like threads and memory, making the service unavailable.

Detection Guidance

Monitor for unusually high connection counts or thread usage on the MOOSDB HTTP server. Check for excessive memory consumption or unresponsive service. Use netstat or ss to inspect active connections to the MOOSDB port.

Impact Analysis

This vulnerability can cause your MOOS core-moos service to become unresponsive or crash due to resource exhaustion. If exploited, it may lead to downtime, disrupting operations that rely on the HTTP server for communication or data processing.

Compliance Impact

This vulnerability causes service unavailability through denial of service, which may impact compliance with standards requiring availability of systems handling sensitive data like GDPR or HIPAA. Unavailability could lead to disruptions in processing or accessing protected information.

Mitigation Strategies

Implement connection and thread limits on the MOOSDB HTTP server. Restrict access via firewall rules to trusted sources only. Update to the latest version of MOOS core-moos if a patch is available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85450. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart