Junglewise Threat Intelligence

CVE-2026-85444: MOOS-IvP buffer over-read in string parsing functions

CVE-2026-85444 · Severity: high · CVSS 7.5 · Published 2026-09-03

Technologies: MOOS-IvP. Vendors: MOOS-IvP.

Executive brief

MOOS-IvP is an open-source autonomy system used to control autonomous marine vehicles and robotic platforms. A buffer over-read vulnerability in whitespace-stripping functions allows attackers to craft malicious network messages that read adjacent memory contents, potentially exposing sensitive data or system state information from running processes.

Technical details

The vulnerability is a buffer over-read in the isQuoted(), isBraced(), and isChevroned() functions in MBUtils.cpp. These functions strip whitespace from strings but incorrectly index into the buffer using the original string length rather than the adjusted length after whitespace removal, causing out-of-bounds memory access. An attacker can craft NODE_REPORT messages with leading or trailing whitespace to trigger the over-read. No authentication is required; exploitation only requires ability to send network messages to an affected MOOS-IvP instance. The impact is limited to information disclosure (memory read access), not code execution.

Affected products

  • MOOS-IvP MOOS-IvP through 24.8.1

Timeline

  • 2026-09-03: disclosed

References

Related threats