CVE-2026-105164: Nasa Cfs

Low severity, CVSS 2.7. EPSS: 0.5% chance of exploitation in the next 30 days.

A flaw has been found in NASA cFS up to 7.0.1. This issue affects the function CFE_FS_ParseInputFileNameEx of the file cfe/modules/fs/fsw/src/cfe_fs_api.c. This manipulation causes out-of-bounds read. Remote exploitation of the attack is possible. The pull request to fix this issue awaits acceptance.

Affected products

  • Nasa Cfs: version 7.0.0 only; version 7.0.1 only

Published 2026-10-04. Last modified 2026-10-06.