Junglewise Threat Intelligence

CVE-2026-18064: NASA core Flight System NULL pointer dereference in HS application

CVE-2026-18064 · Severity: high · CVSS 7.5 · Published 2026-07-30

Executive brief

The NASA core Flight System (cFS) Health and Safety application, which monitors the status of spacecraft and embedded systems, contains a software flaw. An attacker could send a specific command that causes the application to crash, leading to a system-wide processor reset and a total loss of availability for the affected device. This could disrupt critical flight operations or satellite communications.

Technical details

A NULL pointer dereference (CWE-476) exists in the NASA core Flight System (cFS) Health and Safety (HS) application due to an incomplete fix for a previous vulnerability (CVE-2026-15352). The flaw is reachable via a specific command triggered under certain conditions. Successful exploitation allows an unauthenticated network attacker to crash the HS application, which triggers a processor reset and a denial-of-service condition. While an official release fix is under development, a patch is available in the project's development branch starting at commit 828855f.

Affected products

  • NASA core Flight System (cFS) Health and Safety (HS) Application <=v7.0.1

Timeline

  • 2026-07-30: disclosed: Initial publication of ICSA-26-211-06
  • 2026-07-30: advisory: NVD published CVE-2026-18064

References