CVE-2024-25196: Opennav NAV2

Low severity, CVSS 3.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_controller process. This vulnerability is triggerd via sending a crafted .yaml file.

Affected products

  • Opennav NAV2: from 1.1.0, up to and including 1.1.17
  • Openrobotics Robot Operating System: version 2 only

Published 2024-02-20. Last modified 2026-06-17.