CVE-2026-71643
ZJU-FAST-Lab · EGO-Planner-v2
A denial of service vulnerability exists in the EGOReplanFSM component of EGO-Planner-v2, allowing unauthenticated attackers to disrupt system availability.
Executive summary
The ZJU-FAST-Lab EGO-Planner-v2 software is susceptible to a denial of service attack that can render the application unresponsive.
Vulnerability
The vulnerability resides within the EGOReplanFSM component and allows an unauthenticated, remote attacker to trigger a denial of service condition. The flaw is categorized as highly automatable, enabling potential large-scale disruption of affected robotic planning systems.
Business impact
A successful exploitation of this vulnerability results in a complete denial of service for the affected software, causing significant operational downtime for systems relying on the planner. Given the high CVSS score of 7.5, organizations must treat this as a high-risk event, particularly if the component is integrated into time-sensitive or critical robotic path-planning environments.
Remediation
Immediate Action: Since a specific patch version is not currently defined, developers should pull the latest source code from the official repository and verify that the fix implemented in commits following 5c99a95880401e2599638d567abc0e240396cb42 is present.
Proactive Monitoring: Monitor system logs for unexpected crashes or service restarts specifically associated with the EGOReplanFSM module.
Compensating Controls: Implement network-level segmentation to restrict access to the planning interface, ensuring that only trusted entities can communicate with the vulnerable component.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The severity of this vulnerability necessitates immediate attention from administrators and developers overseeing deployments of EGO-Planner-v2. We recommend auditing current deployments against the vulnerable commit hash and transitioning to the latest stable codebase to eliminate the denial of service risk.
History
CVE Brief tracked this CVE 4 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 7.5 (3.1)
- Analyst report written