CVE-2026-85436CWE-191

CVE-2026-85436

High · published September 4, 2026

CVSS v3.1
7.5
EPSS
1%
Percentile
65.9
In the wild
Unconfirmed
What it is

MOOS essential-moos through 10.0.1 contains a buffer overflow vulnerability in CMOOSUDPLink::ReadPktFromArray() that allows remote attackers to corrupt heap memory by sending UDP datagrams with negative declared lengths. Attackers can send crafted UDP packets to the configured UDPListen port to trigger an oversized memcpy operation that writes past the destination buffer, causing heap corruption and denial of service.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
8.7 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS
0.01192 · 65.9th percentile
Weakness
CWE-191 · Integer Underflow (Wrap or Wraparound)
Published
2026-09-04T03:17Z
References (5)
EPSS history
Timeline
  • 05 SEP 03:44Z
    EPSS moved — → 1%
    epss
  • 03 SEP 22:38Z
    MOOS essential-moos through 10.0.1 pMOOSBridge Heap Corruption via Negative UDP Length
    cvelistv5