MOOS-IvP versions through 24.8.1 contain a quadratic processing vulnerability in uFldNodeComms where each new node identity creates a ledger entry and triggers all-pairs distribution work. Attackers can supply unbounded distinct node names in reports to drive the shoreside broker into quadratic processing, delaying or preventing distribution of legitimate node reports.
{
"cna_assigner": "VulnCheck",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85446.json",
"cwe_ids": [
"CWE-407"
]
}"2026-09-05T08:07:39Z"
[
{
"source": "https://github.com/moos-ivp/moos-ivp/commit/477be7e91bf220185d55e5a2a9dba16dbde32c3f",
"target": {
"function": "showReleaseInfo",
"file": "ivp/src/lib_mbutil/ReleaseInfo.cpp"
},
"signature_version": "v1",
"id": "CVE-2026-85446-17eb9c04",
"signature_type": "Function",
"deprecated": false,
"digest": {
"function_hash": "205105793825430045765894660149070176882",
"length": 721.0
}
},
{
"source": "https://github.com/moos-ivp/moos-ivp/commit/477be7e91bf220185d55e5a2a9dba16dbde32c3f",
"target": {
"file": "ivp/src/pMarineViewer/main.cpp"
},
"signature_version": "v1",
"id": "CVE-2026-85446-703d642b",
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"71475089026327374911439190140854268963",
"288109013441206453595364179806630758895",
"108583411300907172617501463823770114997",
"17171581118612079636848717634386598063"
]
}
},
{
"source": "https://github.com/moos-ivp/moos-ivp/commit/477be7e91bf220185d55e5a2a9dba16dbde32c3f",
"target": {
"function": "main",
"file": "ivp/src/pMarineViewer/main.cpp"
},
"signature_version": "v1",
"id": "CVE-2026-85446-9c0df7cc",
"signature_type": "Function",
"deprecated": false,
"digest": {
"function_hash": "118965062358282729215132681048895208743",
"length": 2942.0
}
},
{
"source": "https://github.com/moos-ivp/moos-ivp/commit/477be7e91bf220185d55e5a2a9dba16dbde32c3f",
"target": {
"file": "ivp/src/lib_mbutil/ReleaseInfo.cpp"
},
"signature_version": "v1",
"id": "CVE-2026-85446-b57c450a",
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"221566291563585211413467636629101977597",
"69881209764151303531923320257498233409",
"153719805825789704065453832941046288979",
"196362707078072643545117675400601289962"
]
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85446.json"