CVE-2026-85447: Moos-Ivp

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

MOOS-IvP pRealm through version 24.8.1 accepts unbounded REALMCAST_REQ subscriptions without validating duration or variable list limits. Attackers can register long-lived pipeways with many variables to cause pRealm to generate excessive output indefinitely, exhausting system resources.

Affected products

  • Moos-Ivp Moos-Ivp: up to and including 24.8.1

Published 2026-09-03. Last modified 2026-09-08.