CVE-2026-85446

MOOS-IvP versions through 24.8.1 contain a quadratic processing vulnerability in uFldNodeComms where each new node identity creates a ledger entry and triggers all-pairs distribution work. Attackers can supply unbounded distinct node names in reports to drive the shoreside broker into quadratic processing, delaying or preventing distribution of legitimate node reports.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-03 23:17

Updated : 2026-09-08 20:07


NVD link : CVE-2026-85446

Mitre link : CVE-2026-85446

CVE.ORG link : CVE-2026-85446


JSON object : View

Products Affected

No product.

CWE
CWE-407

Inefficient Algorithmic Complexity