CVE-2026-67974

7.5

NASA · cFS (Core Flight System)

A parser boundary flaw in the Software Bus Network application of NASA cFS v7.0.1 allows unauthenticated remote attackers to cause a Denial of Service via a crafted packet.

Executive summary

NASA cFS v7.0.1 contains a high-severity parser boundary vulnerability that allows unauthenticated remote attackers to trigger a Denial of Service through crafted network packets.

Vulnerability

The vulnerability exists in the Software Bus Network peer subscription message handling. An unauthenticated attacker can send a specially crafted packet to the affected endpoint, triggering a boundary error that results in a service crash.

Business impact

The exploit allows for a complete Denial of Service against the affected application. Given the nature of flight software, this could lead to critical system instability, loss of telemetry, or interruption of mission-critical communication. With a CVSS score of 7.5, the risk is classified as High, reflecting the ease of exploitation over the network without requiring any prior authentication.

Remediation

Immediate Action: Monitor the official NASA cFS GitHub repository for the release of a patch or security advisory addressing the peer subscription message handling flaw. Until a patch is available, isolate the SBN service within a trusted network segment to limit exposure to untrusted traffic.

Proactive Monitoring: Review system and network logs for anomalous packet patterns or repeated service restarts originating from unexpected sources.

Compensating Controls: Implement network-level filtering to restrict access to the Software Bus Network ports to only known, authorized peer nodes.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability presents a significant risk to the availability of the Core Flight System. Security teams should prioritize monitoring the upstream NASA cFS repository for official remediation efforts. Given the critical nature of these systems, applying the forthcoming patch immediately upon release is essential to maintain system integrity and mission continuity.

More NASA CVEs

Sources