CVE-2026-85441CWE-195

CVE-2026-85441

High · published September 4, 2026

CVSS v3.1
7.5
EPSS
0%
Percentile
29.6
In the wild
Unconfirmed
What it is

MOOS core-moos through 10.4.0 fails to validate that serialized string lengths are non-negative in CMOOSMsg::operator>>. Unauthenticated attackers can send a crafted message with a negative length value to the MOOSDB port, causing an unhandled exception that terminates the database process.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
8.7 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS
0.00366 · 29.6th percentile
Weakness
CWE-195 · Signed to Unsigned Conversion Error
Published
2026-09-04T03:17Z
References (5)
EPSS history
Timeline
  • 05 SEP 03:44Z
    EPSS moved — → 0%
    epss
  • 03 SEP 22:38Z
    MOOS core-moos through 10.4.0 MOOSDB Denial of Service via Negative Serialized String Length
    cvelistv5