High severity7.5NVD Advisory· Published Sep 3, 2026
CVE-2026-85446
CVE-2026-85446
Description
MOOS-IvP versions through 24.8.1 contain a quadratic processing vulnerability in uFldNodeComms where each new node identity creates a ledger entry and triggers all-pairs distribution work. Attackers can supply unbounded distinct node names in reports to drive the shoreside broker into quadratic processing, delaying or preventing distribution of legitimate node reports.
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/moos-ivp/moos-ivp/blob/1de9ae146cd63c209e8c3fd81611a4ed2472971b/ivp/src/uFldNodeComms/FldNodeComms.cppnvd
- github.com/moos-ivp/moos-ivp/commit/8e30008d4eb68d83797187bd46e929e6cb06b195nvd
- github.com/moos-ivp/moos-ivp/pull/131nvd
- www.vulncheck.com/advisories/moos-ivp-through-24.8.1-ufldnodecomms-quadratic-processing-denial-of-servicenvd
News mentions
0No linked articles in our index yet.