Denial of Service Vulnerability in fprime Framework by NASA
CVE-2026-67976

7.5HIGH

Key Information:

Vendor

NASA

Vendor
CVE Published:
3 August 2026

What is CVE-2026-67976?

The Ref::SignalGen component of the fprime framework version 4.2.2 is susceptible to a Denial of Service attack due to inadequate validation of user-controlled parameters. This vulnerability enables attackers to exploit the system by supplying unsafe parameters, potentially leading to disruptions in service availability. Organizations utilizing this framework should review their security measures and apply necessary updates to mitigate the risk.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.