Out-of-Bounds Read Vulnerability in NASA cFS Product
CVE-2026-105164

5.1MEDIUM

Key Information:

Vendor

Nasa

Status
Vendor
CVE Published:
4 October 2026

What is CVE-2026-105164?

A vulnerability has been identified in NASA's Core Flight System (cFS) versions up to 7.0.1. The flaw resides in the function CFE_FS_ParseInputFileNameEx located in the file cfe/modules/fs/fsw/src/cfe_fs_api.c, leading to an out-of-bounds read condition. This weakness could be exploited remotely, potentially compromising the system's integrity and confidentiality. A pull request addressing this issue is currently pending acceptance, highlighting the importance of prompt intervention to mitigate risks.

Affected Version(s)

cFS 7.0.0

cFS 7.0.1

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

juntheworld (VulDB User)
VulDB CNA Team
.