CVE-2026-85444

MOOS-IvP through 24.8.1 contains a buffer over-read vulnerability in isQuoted(), isBraced(), and isChevroned() functions that strip whitespace but index using the original string length. Attackers can send NODE_REPORT messages with leading or trailing whitespace to read past buffer bounds and access adjacent memory.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-03 23:17

Updated : 2026-09-08 20:07


NVD link : CVE-2026-85444

Mitre link : CVE-2026-85444

CVE.ORG link : CVE-2026-85444


JSON object : View

Products Affected

No product.

CWE
CWE-125

Out-of-bounds Read