cvedb.io
CVE-2026-5476
MEDIUM · CVSS 4.6
EPSS exploitation probability: 0%
Published 2026-04-03T18:16:26.687 · Last modified 2026-06-17T10:59:06.007

Summary

A vulnerability was identified in NASA cFS up to 7.0.0 on 32-bit. Affected is the function CFE_TBL_ValidateCodecLoadSize of the file cfe/modules/tbl/fsw/src/cfe_tbl_passthru_codec.c. The manipulation leads to integer overflow. The complexity of an attack is rather high. The exploitability is told to be difficult. A fix is planned for the upcoming version milestone of the project.

Affected products

nasa — core_flight_system

Does this affect you?

Add your gear to cvedb and we'll alert you only when nasa ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.