Executive brief
Fast DDS is a widely-used open-source implementation of the DDS (Data Distribution Service) messaging standard used in robotics, autonomous systems, and real-time distributed applications. An attacker who can join a DDS domain can send a specially crafted network message containing a deeply nested filter expression that causes the DDS participant's process to crash due to stack exhaustion. This is a network-based denial-of-service attack requiring only network connectivity to the DDS domain.
Technical details
Fast DDS's DDSSQLFilter component implements SQL-based content filtering using a fully recursive PEG (Parsing Expression Grammar) parser without recursion depth limits, AST depth limits, or practical length limits on filter expressions. When a DDS participant receives a malicious SEDP (RTPS discovery) DCPSSubscription DATA message containing a deeply nested filterExpression (e.g., tens of thousands of nested parentheses), the recursive parser exhausts the thread stack and crashes the process. The attack requires network reachability to the victim's RTPS ports (default multicast 239.255.0.1:7400/7412 or configured unicast) and the attacker must be able to join the DDS domain; with security disabled, any reachable process can join; with security enabled, any authenticated participant can send malicious discovery messages. Patched versions 2.6.12, 2.14.6, 3.2.4, and 3.4.3 address the issue, likely by adding recursion depth limits to the parser.
Affected products
- eProsima Fast DDS prior to 2.6.12, 2.14.6, 3.2.4, and 3.4.3
Timeline
- 2026-07-23: disclosed
- 2026-07-23: patched