CVE-2026-85440: MOOS core-moos through 10.4.0 MOOSDB Pre-Authentication Heap Overflow via Negative Packet Length
MOOS core-moos through 10.4.0 contains a pre-authentication heap overflow vulnerability in MOOSCommPkt packet handling that allows remote attackers to write arbitrary data by declaring a negative packet length. Attackers can exploit the signed integer check in InflateTo() and negative size conversion in recv() to overflow a four-byte heap buffer during the HandShake phase before authentication.
Affected Software
Event History
Frequently Asked Questions
Which installations should be considered affected?
MOOS core-moos through version 10.4.0 is affected, specifically in MOOSDB packet handling. Systems running those versions should be treated as vulnerable.
Does exploitation require valid credentials or prior access?
No. The flaw is reachable during the HandShake phase before authentication, and the vector is remote with no privileges or user interaction required.
How can I determine whether my environment is exposed?
Identify hosts running MOOSDB from MOOS core-moos and verify their installed version. Versions through 10.4.0 fall within the affected range.