PatchSiren

Nasa CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL NASA CVE published 2026-08-10

CVE-2026-72577

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T11:17:30.533Z and has not been modified since then. Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve arbitrary code execution on the ground station host and inject arbitrary commands to connected spacecraft. The Flask application in src [truncated]

HIGH NASA CVE published 2026-08-03

CVE-2026-67975

CVE-2026-67975 is a HIGH-severity vulnerability in NASA cFS v7.0.1, allowing attackers to arbitrarily remove low-index subscriptions and add new streams via TO_LAB add/remove subscription commands. The vulnerability has a CVSS score of 7.5. This issue is related to incorrect access control, which can lead to unauthorized modifications. Affected organizations should prioritize verification of their invento [truncated]

HIGH NASA CVE published 2026-08-03

CVE-2026-67974

A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via sending a crafted packet. This vulnerability has significant implications for organizations utilizing the affected software, as it could be exploited to disrupt service. The flaw is located in the SBN application's peer subscri [truncated]

HIGH NASA CVE published 2026-08-03

CVE-2026-67970

The DS_SetDestPathCmd() component of NASA cFS v7.0.1 has an incorrect access control vulnerability, allowing attackers to access sensitive components via a path traversal. This vulnerability affects organizations using NASA cFS v7.0.1, particularly those in the aerospace and defense sectors. The CVE record was published on 2026-08-03T22:16:51.237Z and has not been modified since then. The debrief is based [truncated]

HIGH NASA CVE published 2026-07-30

CVE-2026-18064

The NASA core Flight System (cFS) Health and Safety (HS) application is vulnerable to a denial-of-service condition due to a NULL pointer dereference. An attacker who can trigger the affected command under specific conditions could cause the HS application to crash, resulting in a denial-of-service condition and processor reset. This vulnerability affects versions through 7.0.1. The incomplete fix for CVE [truncated]

MEDIUM NASA CVE published 2026-05-25

CVE-2018-25367

NASA OpenVSP 3.16.1 contains a buffer overflow vulnerability in the geometry name field handling. A local attacker can trigger denial of service by supplying an excessively long string (approximately 5000 bytes) in the name input field within the Geom browser pod addition interface. The vulnerability results in application crash due to improper bounds checking on user-supplied input. This is a local attac [truncated]

NONE nasa CVE published 2026-04-22

CVE-2026-41144

CVE-2026-41144 affects NASA F Prime prior to version 4.2.0. A U32 overflow in the byteOffset + dataSize bounds check can let a crafted packet bypass validation, and the destination path is not sanitized, allowing writes to arbitrary files at attacker-chosen offsets. The advisory says this can lead to remote code execution on embedded targets, and notes that ASAN will not detect the bug because the corrupt [truncated]

LOW NASA CVE published 2026-04-03

CVE-2026-5476

A vulnerability was identified in NASA cFS up to 7.0.0 on 32-bit systems. The affected function is CFE_TBL_ValidateCodecLoadSize in the file cfe/modules/tbl/fsw/src/cfe_tbl_passthru_codec.c. The manipulation leads to an integer overflow. The complexity of an attack is rather high and the exploitability is difficult. A fix is planned for the upcoming version milestone of the project. Organizations should r [truncated]

LOW NASA CVE published 2026-04-03

CVE-2026-5473

A deserialization vulnerability was found in NASA cFS up to 7.0.0, specifically in the Pickle Module's function pickle.load. The attack requires local access and a high level of complexity, making exploitability difficult. Organizations should assess their exposure and apply mitigations as available. The project was informed but has not yet responded. This vulnerability has a CVSS score of 1.1, indicating [truncated]