CVE-2026-85443
EUVD-2026-7077703.09.2026, 23:17
MOOS core-moos through 10.4.0 contains a denial of service vulnerability in MOOSCommServer::ListenLoop() where the accept thread performs a blocking receive without timeout during the wire-protocol handshake. An attacker can open a TCP connection to the MOOSDB port and send no data, causing the accept thread to block indefinitely while holding the socket-list lock, preventing all subsequent client connections.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
References