Unbounded Memory Consumption in MOOS-IvP pMarineViewer Affects Multiple Versions
CVE-2026-85449

8.7HIGH

Key Information:

Vendor

Moos-ivp

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-85449?

The pMarineViewer component of MOOS-IvP, prior to version 24.8.1, is susceptible to an unbounded memory consumption vulnerability. This issue arises from the failure to limit the number of unique node identities in NODE_REPORT messages, allowing for an attacker to maliciously exploit this by sending numerous distinct node names. Such exploitation can result in memory exhaustion, effectively stalling the operator's display. This vulnerability does not require authentication, making it particularly severe as it can be executed without any user credentials.

Affected Version(s)

moos-ivp 0 <= 24.8.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vlatko Kosturjak
.