The only mosh CVE [1] was in the terminal emulator (a DoS that could only be triggered by a local user), not in the protocol. There have been no vulnerabilities in mosh's UDP protocol.
I wonder if anyone's thrown a fuzzer at it.
[1] https://github.com/google/oss-fuzz/tree/master/projects/mosh