CVE-2026-85448
nicheUnbounded state growth causing denial of service in MOOS-IvP uFldShoreBroker
MOOS-IvP uFldShoreBroker through version 24.8.1 stores claimed communities in parallel vectors without limiting their size in ShoreBroker::handleMailNodePing() (CWE-770). A single publisher that can reach the broker can supply an unbounded number of distinct community names, causing retained state and per-pass work to grow without limit. The result is memory exhaustion and progressive performance degradation, ultimately a denial of service against the shore-side broker (CVSS 4.0 availability impact: High, with no confidentiality or integrity impact). Affected parties are operators of MOOS-IvP-based autonomy stacks — typically marine robotics research groups, competition teams, and naval research deployments — running uFldShoreBroker in shore-side or fielded multi-vehicle missions. No public proof-of-concept exists, the issue is not in CISA KEV, and the EPSS score of 0.4% indicates exploitation is not currently expected or observed.
What to do: Audit whether uFldShoreBroker is deployed in your MOOS-IvP stacks and upgrade to a MOOS-IvP release newer than 24.8.1 once a patched version is published, since no fixed version is specified in the disclosure data. Until then, restrict network access to the shore broker (firewall/ACLs allowing only trusted vehicles and publishers) and monitor its memory footprint and responsiveness for unbounded growth. Coordinate with your autonomy software maintainer or watch the MOOS-IvP repository for the fix, as there is no public PoC to validate against.
| MOOS-IvP uFldShoreBroker | through 24.8.1 (all versions up to and including 24.8.1); no fixed version specified in the data |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
MOOS-IvP uFldShoreBroker through 24.8.1 fails to limit the number of claimed communities stored in parallel vectors within ShoreBroker::handleMailNodePing(). A single publisher can supply unbounded distinct community names to grow retained state and per-pass work without limit, causing memory exhaustion and performance degradation.
- Weakness
- CWE-770
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.