CVE-2026-85446
nicheQuadratic Processing DoS in MOOS-IvP uFldNodeComms Shoreside Broker
MOOS-IvP, the open-source autonomy middleware used in marine robotics, contains an algorithmic complexity flaw (CWE-407) in its uFldNodeComms shoreside application. The component maintains a ledger in which every newly encountered node identity creates an entry and triggers all-pairs distribution work, so an attacker who submits node reports containing many distinct node names drives the shoreside broker into quadratic processing. The practical impact is denial of service: distribution of legitimate node reports is delayed or prevented, with high availability impact and no confidentiality or integrity impact per the CVSS 4.0 score of 8.7. Any operator running MOOS-IvP versions through 24.8.1 with uFldNodeComms active on a shoreside computer during multi-vehicle field operations is exposed, and because the attack path is network-reachable without privileges or user interaction, no special access is required. There is no known exploitation, no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns only a 0.4% probability of exploitation within 30 days.
What to do: Inventory shoreside computers for uFldNodeComms and plan to move to a MOOS-IvP release newer than 24.8.1 once a patched version is published by the project. In the interim, restrict access to the shoreside node communications interface to trusted mission networks (it is reachable unauthenticated per the CVSS vector), and consider limiting or validating the number of distinct node identities accepted into the ledger to cap the quadratic work. No exploitation has been observed, so monitoring vendor channels and patching at the next maintenance cycle is a reasonable posture for most operators.
| MOOS-IvP (open-source project) MOOS-IvP uFldNodeComms shoreside application | all versions through and including 24.8.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
MOOS-IvP versions through 24.8.1 contain a quadratic processing vulnerability in uFldNodeComms where each new node identity creates a ledger entry and triggers all-pairs distribution work. Attackers can supply unbounded distinct node names in reports to drive the shoreside broker into quadratic processing, delaying or preventing distribution of legitimate node reports.
- Weakness
- CWE-407
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.