PatchSiren cyber security CVE debrief
CVE-2026-5473 NASA CVE debrief
A deserialization vulnerability was found in NASA cFS up to 7.0.0, specifically in the Pickle Module's function pickle.load. The attack requires local access and a high level of complexity, making exploitability difficult. Organizations should assess their exposure and apply mitigations as available. The project was informed but has not yet responded. This vulnerability has a CVSS score of 1.1, indicating a low severity. The NVD entry is currently Analyzed.
- Vendor
- NASA
- Product
- cFS
- CVSS
- LOW 1.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-03
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-03
- Advisory updated
- 2026-07-24
Who should care
Organizations using NASA's Core Flight System (cFS) version up to 7.0.0 should assess their exposure and apply mitigations as available. This includes reviewing system logs for suspicious activity related to the Pickle Module and considering compensating controls for local access and complexity. Security teams should prioritize patching or mitigating this vulnerability due to its potential impact on system security.
Technical summary
The vulnerability exists in the pickle.load function of the Pickle Module in NASA cFS up to 7.0.0. Successful exploitation requires local access and a high level of complexity. The CVSS score is 1.1, indicating a low severity. The vulnerability was disclosed publicly and may be used. The project was informed early but has not yet responded. Defensive priorities include applying vendor patches or mitigations as they become available and monitoring systems for unusual activity related to the Pickle Module.
Defensive priority
Apply vendor patches or mitigations as they become available. Monitor systems for unusual activity related to the Pickle Module. Prioritize patching or mitigating this vulnerability due to its potential impact on system security.
Recommended defensive actions
- Inventory affected systems for cFS version up to 7.0.0
- Apply patches or mitigations provided by NASA
- Monitor system logs for suspicious activity related to the Pickle Module
- Consider compensating controls for local access and complexity
- Review and update local access controls and monitoring
- Track exceptions and retest remediated assets
- Verify evidence of mitigation and document results
Evidence notes
The CVE record was published on 2026-04-03T17:16:54.203Z and last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Analyzed. The vulnerability was found in NASA cFS up to 7.0.0. The impacted element is the function pickle.load of the component Pickle Module. Such manipulation leads to deserialization. The attack needs to be performed locally. The attack requires a high level of complexity. The exploitability is regarded as difficult. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet. Evidence limits suggest verifying local access controls and monitoring for unusual activity related to the Pickle Module.
Official resources
-
CVE-2026-5473 CVE record
CVE.org
-
CVE-2026-5473 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
[email protected] - Product
-
Source reference
[email protected] - Issue Tracking
-
Mitigation or vendor reference
[email protected] - Third Party Advisory, VDB Entry
-
Mitigation or vendor reference
[email protected] - Third Party Advisory, VDB Entry
-
Source reference
[email protected] - Permissions Required, VDB Entry
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-03T17:16:54.203Z and has not been modified since then. The NVD entry is currently Analyzed.