CVE-2026-85437
nicheBuffer Overflows in MOOS-IvP IvP String Decoders May Enable Remote Code Execution
MOOS-IvP through 24.8.1 is affected by multiple buffer overflow vulnerabilities (CWE-787, out-of-bounds write) in the IvP function string decoders, which accept attacker-controlled length fields without validating them. An attacker can trigger the flaw by sending crafted encoded strings whose declared field lengths do not match their actual lengths, delivered through MOOS variables or by feeding a crafted alog file to components that parse it. The resulting heap or stack buffer overflows could allow remote code execution with the privileges of the affected MOOS process, per the critical CVSS 4.0 score of 9.3. Anyone running MOOS-IvP up to and including version 24.8.1 — on autonomous vehicle stacks, shore-side ground stations, simulators, or alog post-processing tools — is potentially affected. No public proof-of-concept or confirmed exploitation is known, the flaw is not in CISA KEV, and EPSS currently estimates only a 0.7% chance of exploitation within 30 days.
What to do: Upgrade MOOS-IvP to a release newer than 24.8.1 as soon as a patched version is published (no fixed version is specified in the available data). Until then, treat alog files from untrusted sources as suspect before parsing, and restrict network access to MOOSDB and other MOOS-IvP listeners so only trusted peers can inject MOOS variables. Audit autonomy stacks, shore-side tools, and any analysis software that parses alog files for vulnerable versions.
| MOOS-IvP (open-source project) MOOS-IvP (IvP function string decoders) | all versions through and including 24.8.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
MOOS-IvP through 24.8.1 contains multiple buffer overflow vulnerabilities in IvP function string decoders that trust attacker-controlled length fields without validation. Attackers can craft malicious encoded strings with mismatched declared and actual field lengths to overflow heap and stack buffers, potentially achieving remote code execution through MOOS variables or alog files.
- Weakness
- CWE-787
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.