Impact
MOOS core‑moos up to and including version 10.4.0 contains a denial of service flaw in the MOOSDB HTTP server. The server fails to limit the number of incoming connections and spawned threads, allowing an attacker to open many connections and send large amounts of header data. The unbounded resource usage can exhaust available threads and memory, leading to service unavailability.
Affected Systems
The vulnerability affects the MOOS core‑moos suite produced by themoos, specifically all releases through version 10.4.0.
Risk and Exploitability
The CVSS score for this vulnerability is 8.7, indicating a high severity. No EPSS score is available and the vulnerability is not listed in CISA’s KEV catalog, so exploitation likelihood is uncertain. Based on the description, it is inferred that an attacker can trigger the issue by connecting to the MOOSDB HTTP server over HTTP and repeatedly sending large header fields to consume server resources. An attacker with network access to the server could bring the service to a halt by exhausting available threads and memory.
OpenCVE Enrichment