Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 04 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nasa core Flight System
|
|
| CPEs | cpe:2.3:a:nasa:core_flight_system:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nasa core Flight System
|
Sat, 04 Apr 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 03 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in NASA cFS up to 7.0.0 on 32-bit. Affected is the function CFE_TBL_ValidateCodecLoadSize of the file cfe/modules/tbl/fsw/src/cfe_tbl_passthru_codec.c. The manipulation leads to integer overflow. The complexity of an attack is rather high. The exploitability is told to be difficult. A fix is planned for the upcoming version milestone of the project. | |
| Title | NASA cFS cfe_tbl_passthru_codec.c CFE_TBL_ValidateCodecLoadSize integer overflow | |
| First Time appeared |
Nasa
Nasa cfs |
|
| Weaknesses | CWE-189 CWE-190 |
|
| CPEs | cpe:2.3:a:nasa:cfs:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nasa
Nasa cfs |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-04-04T03:20:03.080Z
Reserved: 2026-04-03T07:51:24.742Z
Link: CVE-2026-5476
Updated: 2026-04-04T03:19:57.698Z
Status : Analyzed
Published: 2026-04-03T18:16:26.687
Modified: 2026-05-04T14:19:34.667
Link: CVE-2026-5476
No data.
OpenCVE Enrichment
Updated: 2026-04-03T21:15:02Z