GHSA-387j-4pfq-cmj4HighCVSS 7.5

MOOS-IvP versions through 24.8.1 contain a quadratic processing vulnerability in uFldNodeComms...

Published
September 4, 2026
Last Modified
September 4, 2026

🔗 CVE IDs covered (1)

📋 Description

MOOS-IvP versions through 24.8.1 contain a quadratic processing vulnerability in uFldNodeComms where each new node identity creates a ledger entry and triggers all-pairs distribution work. Attackers can supply unbounded distinct node names in reports to drive the shoreside broker into quadratic processing, delaying or preventing distribution of legitimate node reports.

🔗 References (7)