Out-of-Bounds Read Vulnerability in TIER IV Nebula from Tier IV
CVE-2026-74238

8.7HIGH

Key Information:

Vendor

Tier4

Status
Vendor
CVE Published:
17 August 2026

What is CVE-2026-74238?

TIER IV Nebula versions up to 1.2.0 contain an out-of-bounds read vulnerability in the Vlp32Decoder::unpack() function. This flaw allows unauthenticated remote attackers to exploit the decoder by sending short malformed UDP datagrams. The vulnerability permits the attacker to read past the end of a UDP buffer into adjacent heap memory. This can lead to unauthorized data being published in downstream PointCloud2 messages consumed by Autoware nodes, potentially impacting the integrity and security of data processing in autonomous systems.

Affected Version(s)

nebula 0 <= 1.2.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Fatullayev Asadbek
.