CVE-2026-85447

Summary

MOOS-IvP pRealm through version 24.8.1 accepts unbounded REALMCAST_REQ subscriptions without validating duration or variable list limits. Attackers can register long-lived pipeways with many variables to cause pRealm to generate excessive output indefinitely, exhausting system resources.

Affected Software

VendorProductVersion RangeStatus
moos-ivpmoos-ivp0 <= 24.8.1affected

Weaknesses

  • CWE-770: Allocation of Resources Without Limits or Throttling

References