MOOS-IvP versions through 24.8.1 contain a quadratic processing vulnerability in uFldNodeComms where each new node identity creates a ledger entry and triggers all-pairs distribution work. Attackers can supply unbounded distinct node names in reports to drive the shoreside broker into quadratic processing, delaying or preventing distribution of legitimate node reports.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-03 23:17
Updated : 2026-09-08 20:07
NVD link : CVE-2026-85446
Mitre link : CVE-2026-85446
CVE.ORG link : CVE-2026-85446
JSON object : View
Products Affected
No product.
CWE
CWE-407
Inefficient Algorithmic Complexity
