CVE-2026-85448
Received Received - Intake

Memory Exhaustion in MOOS-IvP uFldShoreBroker

Vulnerability report for CVE-2026-85448, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-03

Last updated on: 2026-09-03

Assigner: VulnCheck

Description

MOOS-IvP uFldShoreBroker through 24.8.1 fails to limit the number of claimed communities stored in parallel vectors within ShoreBroker::handleMailNodePing(). A single publisher can supply unbounded distinct community names to grow retained state and per-pass work without limit, causing memory exhaustion and performance degradation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-03
Last Modified
2026-09-03
Generated
2026-09-04
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
moos-ivp ufldshorebroker to 24.8.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

MOOS-IvP uFldShoreBroker through version 24.8.1 has a flaw where it does not restrict the number of claimed communities stored in memory. A malicious publisher can send an unlimited number of distinct community names, causing the system to consume excessive memory and slow down due to unbounded state growth.

Detection Guidance

This vulnerability can be detected by monitoring memory usage and performance degradation in systems running MOOS-IvP uFldShoreBroker through version 24.8.1. Check for unbounded growth in claimed communities by examining process memory and logs for excessive community name storage.

Impact Analysis

This vulnerability can lead to denial-of-service conditions by exhausting system memory and degrading performance. If exploited, it may cause applications relying on MOOS-IvP uFldShoreBroker to crash or become unresponsive, disrupting operations that depend on this software.

Compliance Impact

This vulnerability causes memory exhaustion and performance degradation due to unbounded state growth from unchecked community names. While not directly tied to GDPR or HIPAA, such resource exhaustion could lead to system instability or denial of service, potentially impacting availability requirements in these standards.

Mitigation Strategies

Immediately update MOOS-IvP uFldShoreBroker to the latest version beyond 24.8.1. If an update is unavailable, restrict network access to the ShoreBroker service to limit exposure. Monitor system resources for signs of memory exhaustion.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85448. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart