{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-85450","assignerOrgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","state":"PUBLISHED","assignerShortName":"VulnCheck","dateReserved":"2026-09-03T19:51:01.301Z","datePublished":"2026-09-03T22:38:38.316Z","dateUpdated":"2026-09-04T17:19:42.406Z"},"containers":{"cna":{"providerMetadata":{"orgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","shortName":"VulnCheck","dateUpdated":"2026-09-03T22:38:38.316Z"},"datePublic":"2026-09-01T00:00:00.000Z","title":"MOOS core-moos through 10.4.0 MOOSDB HTTP Server Resource Exhaustion","descriptions":[{"lang":"en","value":"MOOS core-moos through 10.4.0 contains a denial of service vulnerability in the MOOSDB HTTP server that creates unbounded connections and threads without limits. Attackers can open many connections and send endless header data to exhaust server threads and memory, causing service unavailability."}],"problemTypes":[{"descriptions":[{"lang":"en","description":"Allocation of Resources Without Limits or Throttling","cweId":"CWE-770","type":"CWE"}]}],"affected":[{"vendor":"themoos","product":"core-moos","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"10.4.0","status":"affected","versionType":"custom"}]}],"metrics":[{"cvssV4_0":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","baseScore":8.7,"baseSeverity":"HIGH"}},{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}],"references":[{"url":"https://github.com/themoos/core-moos/pull/79","tags":["issue-tracking","patch"],"name":"Pull Request #79"},{"url":"https://github.com/themoos/core-moos/commit/dfef92b3bc31886bc47e4d680aef583b78cb8d72","tags":["patch"],"name":"Proposed fix commit (pull request not merged)"},{"url":"https://github.com/themoos/core-moos","tags":["product"]},{"url":"https://github.com/themoos/core-moos/blob/ec9c77c68fcbdef8f5e4c60fe243acd223433f0c/Core/libMOOS/DB/HTTPConnection.cpp#L167","tags":["technical-description"],"name":"HTTPConnection.cpp (verified sink)"},{"name":"VulnCheck Advisory: MOOS core-moos through 10.4.0 MOOSDB HTTP Server Resource Exhaustion","tags":["third-party-advisory"],"url":"https://www.vulncheck.com/advisories/moos-core-moos-through-10.4.0-moosdb-http-server-resource-exhaustion"}],"credits":[{"lang":"en","value":"Vlatko Kosturjak","type":"finder"}],"x_generator":{"engine":"vulncheck-endgame"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-04T17:19:31.676945Z","id":"CVE-2026-85450","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-04T17:19:42.406Z"}}]}}