Junglewise Threat Intelligence

CVE-2026-85447: MOOS-IvP pRealm unbounded REALMCAST_REQ subscription denial of service

CVE-2026-85447 · Severity: high · CVSS 7.5 · Published 2026-09-03

Vendors: MOOS-IvP.

Executive brief

MOOS-IvP pRealm is an autonomy module for robotic platforms that manages data subscriptions and distribution. An attacker can register data subscriptions with excessive duration and variable counts, causing pRealm to generate unlimited output and exhaust system memory and CPU, making the autonomous vehicle unavailable for operation.

Technical details

MOOS-IvP pRealm accepts REALMCAST_REQ subscription requests without validating limits on subscription duration or the number of variables per subscription. An unauthenticated network attacker can send malicious REALMCAST_REQ messages with long-lived duration values and large variable lists to cause pRealm to enter an unbounded message generation loop. This exhausts system resources (memory and CPU), resulting in a denial of service. The vulnerable component is the PipeWay subscription handler in pRealm. A patch validating subscription parameters is required to fix this issue.

Affected products

  • MOOS-IvP pRealm through 24.8.1

Timeline

  • 2026-09-03: disclosed: CVE-2026-85447 published

References