Stack-Based Buffer Overflow in NASA Trick TCP Socket Handler
CVE-2026-82478

6.9MEDIUM

Key Information:

Vendor

Nasa

Status
Vendor
CVE Published:
30 August 2026

What is CVE-2026-82478?

A remote exploitation vulnerability was identified in NASA Trick version 19.6.0 affecting the TCP Socket Handler component. The issue lies within the JSONVariableServerThread::parse_request function located in trick_source/sim_services/JSONVariableServer/JSONVariableServerThread.cpp, where improper handling of input can lead to a stack-based buffer overflow. This vulnerability allows an attacker to manipulate requests sent to the JSON Variable Server, potentially compromising the application. Despite being contacted about the vulnerability disclosure, the vendor has not responded.

Affected Version(s)

Trick 19.6.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

juntheworld (VulDB User)
VulDB CNA Team
.