Quadratic Processing Vulnerability in MOOS-IvP Affecting Node Communication
CVE-2026-85446

8.7HIGH

Key Information:

Vendor

Moos-ivp

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-85446?

A quadratic processing vulnerability exists in the uFldNodeComms component of MOOS-IvP, where each new node identity can lead to excessive ledger entries that overload the shoreside broker. By supplying unbounded unique node names, attackers can exploit this flaw to cause significant delays or even halt legitimate node report distributions, compromising the operational efficiency and reliability of the affected systems.

Affected Version(s)

moos-ivp 0 <= 24.8.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vlatko Kosturjak
.