CVE-2026-102809: PX4 PX4-Autopilot

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

PX4 Autopilot through 1.17.0 contains an uncontrolled stack allocation vulnerability in the file2 test command that fails to validate the write chunk size parameter. Attackers with shell access can supply an excessively large value to the -c option to trigger stack overflow and crash the flight controller.

Affected products

  • PX4 PX4-Autopilot: up to and including 1.17.0

Published 2026-09-29. Last modified 2026-09-30.