CVE-2026-85450: Themoos Core-Moos

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

MOOS core-moos through 10.4.0 contains a denial of service vulnerability in the MOOSDB HTTP server that creates unbounded connections and threads without limits. Attackers can open many connections and send endless header data to exhaust server threads and memory, causing service unavailability.

Affected products

  • Themoos Core-Moos: up to and including 10.4.0

Published 2026-09-03. Last modified 2026-09-08.