CVE-2026-85447
nicheResource exhaustion DoS in MOOS-IvP pRealm via unbounded REALMCAST_REQ subscriptions
MOOS-IvP pRealm, the realm-cast component of the MOOS-IvP autonomy middleware, through version 24.8.1 accepts REALMCAST_REQ subscription requests without validating subscription duration or limiting the size of requested variable lists. An unauthenticated network attacker can register long-lived pipeways with large variable lists, causing pRealm to generate excessive output indefinitely. This uncontrolled resource consumption (CWE-770) exhausts system resources on the host running pRealm, yielding a denial of service; the CVSS 4.0 score of 8.7 reflects high availability impact with no confidentiality or integrity impact. Anyone running pRealm in MOOS-IvP releases up to and including 24.8.1 — typically marine-robotics research groups, autonomy labs, and unmanned vehicle stacks — is affected. No public proof-of-concept or in-the-wild exploitation is known; EPSS estimates only a ~0.4% probability of exploitation within 30 days and the flaw is not in CISA KEV.
What to do: Upgrade to a MOOS-IvP release newer than 24.8.1 when the patched version is available, and verify deployed builds by checking the MOOS-IvP release/version in use. Until patching, restrict access to pRealm's realm-cast ports to trusted networks only (firewall/ACLs), since the flaw requires no privileges or user interaction, and monitor hosts running pRealm for sustained CPU/memory growth. Operators can also rate-limit or filter unexpected REALMCAST_REQ traffic at the network edge to bound subscription abuse.
| MOOS-IvP (open-source project) pRealm (realm-cast component) | all versions through and including 24.8.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
MOOS-IvP pRealm through version 24.8.1 accepts unbounded REALMCAST_REQ subscriptions without validating duration or variable list limits. Attackers can register long-lived pipeways with many variables to cause pRealm to generate excessive output indefinitely, exhausting system resources.
- Weakness
- CWE-770
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.