Security Advisory

CVE-2026-85446

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-03 22:38:35
Last updated 2026-09-04 13:40:40
Assigner VulnCheck
CVSS score 8.7
State PUBLISHED

Description

MOOS-IvP versions through 24.8.1 contain a quadratic processing vulnerability in uFldNodeComms where each new node identity creates a ledger entry and triggers all-pairs distribution work. Attackers can supply unbounded distinct node names in reports to drive the shoreside broker into quadratic processing, delaying or preventing distribution of legitimate node reports.