VYPR

core-moos

by MOOS

Source repositories

CVEs (2)

  • CVE-2026-85443HigSep 3, 2026
    risk 0.42cvss 7.5epss 0.00

    MOOS core-moos through 10.4.0 contains a denial of service vulnerability in MOOSCommServer::ListenLoop() where the accept thread performs a blocking receive without timeout during the wire-protocol handshake. An attacker can open a TCP connection to the MOOSDB port and send no…

  • CVE-2026-85453MedSep 3, 2026
    risk 0.33cvss 6.1epss 0.00

    MOOS core-moos through 10.4.0 fails to escape database contents when rendering MOOSDB HTTP pages, allowing attackers to inject malicious scripts. Any MOOS publisher can set variable values containing script payloads that execute in the browser of operators viewing the web…