Integer Overflow Vulnerability in NASA cFS Software by NASA
CVE-2026-5476

2.1LOW

Key Information:

Vendor

Nasa

Status
Vendor
CVE Published:
3 April 2026

What is CVE-2026-5476?

A significant integer overflow vulnerability has been identified in NASA's cFS software, specifically in the CFE_TBL_ValidateCodecLoadSize function within the cfe_tbl_passthru_codec.c file. This flaw affects versions of NASA cFS up to 7.0.0 on 32-bit systems, and while the complexity of exploiting this vulnerability is classified as high, the actual exploitability is noted to be challenging. A resolution is in the pipeline with plans for a fix in an upcoming version milestone.

Affected Version(s)

cFS 7.0

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

0rbitingZer0 (VulDB User)
VulDB CNA Team
.