---
id: CVE-2026-85445
title: >-
  MOOS-IvP through 24.8.1 contains a denial of service vulnerability in the
  Demuxer::addMuxPacket() function that trusts the packet count declared in mux
  headers without validation
summary: >-
  MOOS-IvP through 24.8.1 contains a denial of service vulnerability in the
  Demuxer::addMuxPacket() function that trusts the packet count declared in mux
  headers without validation. Attackers can declare arbitrarily large packet
  counts to …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-789
published: '2026-09-03'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:07:17.943'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85445'
references:
  - url: 'https://github.com/moos-ivp/moos-ivp'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/moos-ivp/moos-ivp/blob/1de9ae146cd63c209e8c3fd81611a4ed2472971b/ivp/src/lib_ivpbuild/Demuxer.cpp#L79
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/moos-ivp/moos-ivp/commit/fc5649ac12915f66a9f09520cdb6b14bc6d77595
    label: disclosure@vulncheck.com
  - url: 'https://github.com/moos-ivp/moos-ivp/pull/129'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/moos-ivp-through-24.8.1-bhv-ipf-demultiplexer-memory-exhaustion-via-packet-count
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.0063
epssPercentile: 0.47888
ingestedAt: '2026-09-08T20:10:03.161Z'
---

## Overview

MOOS-IvP through 24.8.1 contains a denial of service vulnerability in the Demuxer::addMuxPacket() function that trusts the packet count declared in mux headers without validation. Attackers can declare arbitrarily large packet counts to trigger unbounded memory allocation, exhausting system resources and causing service unavailability.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
