CVE-2026-5475: Nasa Core Flight System

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability was determined in NASA cFS up to 7.0.0. This impacts the function CFE_SB_TransmitMsg of the file cfe_sb_priv.c of the component CCSDS Header Size Handler. Executing a manipulation can lead to memory corruption. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

  • Nasa Core Flight System: up to and including 7.0.0

Published 2026-04-03. Last modified 2026-07-24.