CVE-2026-85446: MOOS-IvP through 24.8.1 uFldNodeComms Quadratic Processing Denial of Service
MOOS-IvP versions through 24.8.1 contain a quadratic processing vulnerability in uFldNodeComms where each new node identity creates a ledger entry and triggers all-pairs distribution work. Attackers can supply unbounded distinct node names in reports to drive the shoreside broker into quadratic processing, delaying or preventing distribution of legitimate node reports.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MOOS-IvP (uFldNodeComms)to a version that resolves this vulnerability.Fixed in 24.8.1
Event History
Frequently Asked Questions
Which deployments are exposed to this denial-of-service condition?
MOOS-IvP deployments using uFldNodeComms are exposed if they process reports containing attacker-controlled node identities. The affected component is the shoreside broker, where ledger growth and all-pairs distribution work can delay or prevent legitimate report distribution.
What does an attacker need to do to trigger the issue?
An attacker needs to submit reports with an unbounded number of distinct node names. No privileges or user interaction are required according to the supplied severity vector.
How can I tell whether the broker is being affected?
Look for a growing number of distinct node identities in reports alongside increased shoreside broker processing and delayed or missing distribution of legitimate node reports. The issue is driven by new identities creating ledger entries and triggering all-pairs work.