MOOS core-moos through 10.4.0 fails to validate that...
High severity
Unreviewed
Published
Sep 4, 2026
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Sep 3, 2026
Published to the GitHub Advisory Database
Sep 4, 2026
MOOS core-moos through 10.4.0 fails to validate that serialized string lengths are non-negative in CMOOSMsg::operator>>. Unauthenticated attackers can send a crafted message with a negative length value to the MOOSDB port, causing an unhandled exception that terminates the database process.
References