CVE-2026-85443: Themoos Core-Moos
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
MOOS core-moos through 10.4.0 contains a denial of service vulnerability in MOOSCommServer::ListenLoop() where the accept thread performs a blocking receive without timeout during the wire-protocol handshake. An attacker can open a TCP connection to the MOOSDB port and send no data, causing the accept thread to block indefinitely while holding the socket-list lock, preventing all subsequent client connections.
Affected products
- Themoos Core-Moos: up to and including 10.4.0
Published 2026-09-03. Last modified 2026-09-14.