Executive brief
The NASA core Flight System (cFS) Health and Safety application, which monitors the status of spacecraft and embedded systems, contains a software flaw. An attacker could send a specific command that causes the application to crash, leading to a system-wide processor reset and a total loss of availability for the affected device. This could disrupt critical flight operations or satellite communications.
Technical details
A NULL pointer dereference (CWE-476) exists in the NASA core Flight System (cFS) Health and Safety (HS) application due to an incomplete fix for a previous vulnerability (CVE-2026-15352). The flaw is reachable via a specific command triggered under certain conditions. Successful exploitation allows an unauthenticated network attacker to crash the HS application, which triggers a processor reset and a denial-of-service condition. While an official release fix is under development, a patch is available in the project's development branch starting at commit 828855f.
Affected products
- NASA core Flight System (cFS) Health and Safety (HS) Application <=v7.0.1
Timeline
- 2026-07-30: disclosed: Initial publication of ICSA-26-211-06
- 2026-07-30: advisory: NVD published CVE-2026-18064