ZeroHour

CVE-2026-85446

niche

Quadratic Processing DoS in MOOS-IvP uFldNodeComms Shoreside Broker

CVSS 4.0
8.7 high
EPSS
<1%p28
Published
()
Modified
AI analysis

MOOS-IvP, the open-source autonomy middleware used in marine robotics, contains an algorithmic complexity flaw (CWE-407) in its uFldNodeComms shoreside application. The component maintains a ledger in which every newly encountered node identity creates an entry and triggers all-pairs distribution work, so an attacker who submits node reports containing many distinct node names drives the shoreside broker into quadratic processing. The practical impact is denial of service: distribution of legitimate node reports is delayed or prevented, with high availability impact and no confidentiality or integrity impact per the CVSS 4.0 score of 8.7. Any operator running MOOS-IvP versions through 24.8.1 with uFldNodeComms active on a shoreside computer during multi-vehicle field operations is exposed, and because the attack path is network-reachable without privileges or user interaction, no special access is required. There is no known exploitation, no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns only a 0.4% probability of exploitation within 30 days.

What to do: Inventory shoreside computers for uFldNodeComms and plan to move to a MOOS-IvP release newer than 24.8.1 once a patched version is published by the project. In the interim, restrict access to the shoreside node communications interface to trusted mission networks (it is reachable unauthenticated per the CVSS vector), and consider limiting or validating the number of distinct node identities accepted into the ledger to cap the quadratic work. No exploitation has been observed, so monitoring vendor channels and patching at the next maintenance cycle is a reasonable posture for most operators.

Affected
MOOS-IvP (open-source project) MOOS-IvP uFldNodeComms shoreside applicationall versions through and including 24.8.1
Estimated exposure
nichelikely hundreds to low thousands of deployments worldwide (research- and government-operated marine autonomy fleets) — MOOS-IvP is a specialized open-source autonomy middleware with adoption concentrated in academic, government, and research marine robotics programs, for which no public install-count telemetry exists, so the estimate is an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

MOOS-IvP versions through 24.8.1 contain a quadratic processing vulnerability in uFldNodeComms where each new node identity creates a ledger entry and triggers all-pairs distribution work. Attackers can supply unbounded distinct node names in reports to drive the shoreside broker into quadratic processing, delaying or preventing distribution of legitimate node reports.

Weakness
CWE-407
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.