CVE-2026-5474Disclosure(nasa / core_flight_system)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in NASA cFS up to 7.0.0. This affects the function CFE_MSG_GetSize of the file apps/to_lab/fsw/src/to_lab_passthru_encode.c of the component CCSDS Packet Header Handler. Performing a manipulation results in heap-based buffer overflow. The attacker must have access to the local network to execute the attack. The project was informed of the problem early through an issue report but has not responded yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • core_flight_system

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
core_flight_system

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-03: 2Technical Details · 2026-04-03: 204-03
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5474 - NASA cFS CCSDS Packet Header to_lab_passthru_encode.c CFE_MSG_GetSize heap-based overflow Intel Report: https://ift.tt/ftRAb6g

    Post summary

    The alert announces a newly identified CVE‑2026‑5474 vulnerability—a heap‑based overflow in NASA cFS CCSDS packet header processing—providing technical details but lacking evidence of exploit, PoC, or patch information.

    0000047
    281 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5474 A vulnerability was found in NASA cFS up to 7.0.0. This affects the function CFE_MSG_GetSize of the file apps/to_lab/fsw/src/to_lab_passthru_encode.c of the component C… https://www.cve.org/CVERecord?id=CVE-2026-5474

    Post summary

    The text announces the discovery of a CVE-2026-5474 vulnerability in NASA cFS up to version 7.0.0, detailing the affected function and file.

    0000061
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnasacore_flight_system---

Explore more