CVE-2026-71646

Robotics-STAR-Lab · RACER

A denial of service vulnerability exists in the RACER robotics framework via the FastExplorationFSM::optTimerCallback function, allowing unauthenticated remote attackers to crash the service.

Executive summary

A high-severity denial of service vulnerability in the Robotics-STAR-Lab RACER framework allows unauthenticated remote attackers to disrupt system availability.

Vulnerability

This vulnerability is a denial of service flaw triggered via the FastExplorationFSM::optTimerCallback function in the swarm exploration manager. The attack vector is network based and requires no authentication or user interaction to execute.

Business impact

Successful exploitation of this vulnerability results in a complete denial of service for the affected robotics system. Given the CVSS score of 7.5, this poses a significant risk to operational continuity, potentially halting autonomous operations or research tasks that rely on the RACER framework.

Remediation

Immediate Action: Review the project repository for official patches or updates that address the identified commit. If no official release is available, restrict network access to the affected components to prevent unauthorized interaction with the vulnerable callback function.

Proactive Monitoring: Monitor system logs for repeated crashes or unexpected termination of the swarm exploration manager process. Alerting should be configured for high frequency restarts of the service.

Compensating Controls: Implement network segmentation to isolate the robotics control environment from untrusted networks, thereby reducing the exposure of the vulnerable interface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing the RACER framework should prioritize tracking the provided GitHub issue for upstream fixes. Given the potential for service disruption, administrators should ensure that the affected systems are not exposed to public networks until a formal patch is applied and verified.

More Robotics-STAR-Lab CVEs

History

CVE Brief tracked this CVE 4 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 7.5 (3.1)
  4. Analyst report written

Sources