CVE-2026-85446
Received Received - Intake

Quadratic Processing Flaw in MOOS-IvP uFldNodeComms

Vulnerability report for CVE-2026-85446, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-03

Last updated on: 2026-09-03

Assigner: VulnCheck

Description

MOOS-IvP versions through 24.8.1 contain a quadratic processing vulnerability in uFldNodeComms where each new node identity creates a ledger entry and triggers all-pairs distribution work. Attackers can supply unbounded distinct node names in reports to drive the shoreside broker into quadratic processing, delaying or preventing distribution of legitimate node reports.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-03
Last Modified
2026-09-03
Generated
2026-09-04
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
moos-ivp moos-ivp to 24.8.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-407 An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in MOOS-IvP versions through 24.8.1, specifically in the uFldNodeComms component. It involves a quadratic processing issue where each new node identity creates a ledger entry and triggers all-pairs distribution work. Attackers can exploit this by sending reports with unbounded distinct node names, causing the shoreside broker to perform excessive processing that delays or prevents legitimate node reports from being distributed.

Detection Guidance

Monitor for unusual CPU or memory usage spikes in MOOS-IvP processes, particularly uFldNodeComms. Check for excessive ledger entries or delayed report distribution. Inspect network traffic for unbounded distinct node names being reported.

Impact Analysis

This vulnerability can lead to denial-of-service conditions where legitimate node reports are delayed or blocked due to the shoreside broker being overwhelmed by excessive processing. This could disrupt communication and coordination in systems relying on MOOS-IvP, potentially causing operational delays or failures.

Compliance Impact

This vulnerability does not directly impact compliance with GDPR, HIPAA, or similar standards as it primarily affects system performance and availability rather than data confidentiality, integrity, or privacy. The issue causes delays in legitimate node report distribution due to quadratic processing, which may indirectly affect system reliability but does not inherently violate compliance requirements.

Mitigation Strategies

Update MOOS-IvP to version 24.8.1 or later. Implement rate limiting on node name submissions. Restrict network access to the shoreside broker to trusted sources only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85446. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart