Buffer Over-read Vulnerability in MOOS-IvP by MOOS Project
CVE-2026-85444

8.7HIGH

Key Information:

Vendor

Moos-ivp

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-85444?

The MOOS-IvP software suite, specifically through version 24.8.1, presents a buffer over-read vulnerability affecting the functions isQuoted(), isBraced(), and isChevroned(). This vulnerability arises due to improper management of whitespace when processing NODE_REPORT messages, allowing attackers to potentially read beyond allocated buffers and access adjacent memory. By exploiting this weakness, malicious parties could manipulate inputs with leading or trailing whitespace, thereby endangering the integrity and security of the application.

Affected Version(s)

moos-ivp 0 <= 24.8.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vlatko Kosturjak
.