CVE-2026-74238Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerability in the Vlp32Decoder::unpack() function that allows unauthenticated remote attackers to cause the decoder to read past the end of a received UDP buffer into adjacent heap memory by sending a short UDP datagram. Attackers can send a malformed datagram to the Velodyne UDP sensor port, which lacks sender-address restrictions present in other drivers, causing fabricated points derived from heap memory contents to be silently published into downstream PointCloud2 messages consumed by Autoware nodes.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-17: 2Technical Details · 2026-08-17: 208-17
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-74238 TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerability in the Vlp32Decoder::unpack() function that allows unauthenticated remote attackers to cause… https://www.cve.org/CVERecord?id=CVE-2026-74238 ----- Traducción: CVE-2026-74238 TIE… https://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑74238, detailing an out‑of‑bounds read flaw in Tier IV Nebula 1.2.0 that could enable unauthenticated remote attackers.

    0000026
    100 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-74238 TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerability in the Vlp32Decoder::unpack() function that allows unauthenticated remote attackers to cause… https://www.cve.org/CVERecord?id=CVE-2026-74238

    Post summary

    The text announces an out-of-bounds read flaw (CVE-2026-74238) in TIER IV Nebula's Vlp32Decoder::unpack() function, but provides no evidence of exploitation, tools, or fixes.

    000001.5K
    58.0K followersView on X

Explore more