Junglewise Threat Intelligence

CVE-2026-38891: Open Robotics gazebo_plugins improper input validation in gazebo_ros_diff_drive.cpp

CVE-2026-38891 · Severity: info · CVSS 5.3 · Published 2026-07-01

Executive brief

A vulnerability exists in a common robotics simulation plugin used to control differential drive robots. An attacker can send specially crafted movement commands that cause the simulation to crash or behave erratically. This can disrupt testing environments and lead to a denial of service for researchers or developers relying on the simulation.

Technical details

The Gazebo ROS Diff Drive plugin fails to validate input received on the /cmd_vel topic. Specifically, the gazebo_ros_diff_drive.cpp component does not check for finite values or range constraints in geometry_msgs::Twist messages. An attacker can publish a message containing non-finite values (such as NaN) to the /cmd_vel topic, which propagates into internal motion control states, wheel velocity computations, and odometry integration. This results in corrupted odometry output and a Denial of Service (DoS) by making the robot motion unstable or crashing the plugin.

Affected products

  • Open Robotics gazebo_plugins 3.9.0

Timeline

  • 2026-07-01: disclosed
  • 2026-07-01: advisory

References