CVE-2026-71645
Robotics-STAR-Lab · RACER
A vulnerability in the Robotics-STAR-Lab RACER exploration state machine allows unauthenticated attackers to cause a denial of service.
Executive summary
A high-severity denial of service vulnerability in the Robotics-STAR-Lab RACER software allows remote, unauthenticated attackers to crash the exploration state machine.
Vulnerability
The vulnerability exists within the exploration state machine component of the RACER software, which fails to properly handle certain inputs. As indicated by the CVSS vector AV:N/AC:L/PR:N, this flaw is remotely exploitable by an unauthenticated attacker without requiring special privileges or user interaction.
Business impact
The successful exploitation of this vulnerability results in a denial of service, which can cause significant operational disruption for systems utilizing the RACER framework. With a CVSS score of 7.5, the risk to service availability is substantial, potentially halting automated processes or robotic operations that rely on the affected state machine.
Remediation
Immediate Action: Review the official Robotics-STAR-Lab repository for updates or patches addressing the identified commit. If a stable release is unavailable, restrict network access to the affected service to trusted internal segments only.
Proactive Monitoring: Monitor system logs for repeated crashes or unusual error messages associated with the exploration state machine. Identify and alert on spikes in traffic directed at the service that might indicate a denial of service attempt.
Compensating Controls: Deploy a network firewall or intrusion prevention system to filter anomalous traffic patterns directed at the service ports used by RACER.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The high CVSS score of 7.5 highlights the potential for significant service interruption. Organizations deploying the RACER framework must prioritize identifying instances of the affected commit in their environment and implementing network-level restrictions. Continue to monitor the upstream repository for a formal release or security guidance to permanently resolve this denial of service risk.
More Robotics-STAR-Lab CVEs
History
CVE Brief tracked this CVE 5 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 7.5 (3.1)
- Analyst report written