CVE-2026-85447: MOOS-IvP through 24.8.1 pRealm Unbounded REALMCAST_REQ Subscription Denial of Service
MOOS-IvP pRealm through version 24.8.1 accepts unbounded REALMCASTREQ subscriptions without validating duration or variable list limits. Attackers can register long-lived pipeways with many variables to cause pRealm to generate excessive output indefinitely, exhausting system resources.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MOOS-IvP pRealmto a version that resolves this vulnerability.Fixed in 24.8.1
Event History
Frequently Asked Questions
Does exploiting this issue require authentication or user interaction?
No. The severity vector indicates network reachability, low attack complexity, no privileges required, and no user interaction.
Which deployments are affected?
The affected component is pRealm in MOOS-IvP through version 24.8.1. The provided information does not identify a fixed release version.
What is the expected security impact?
The impact is denial of service through resource exhaustion caused by excessive, long-lived output generation. The severity vector indicates no confidentiality or integrity impact.