CVE-2026-5476
Severity CVSS v4.0:
LOW
Type:
CWE-189
Numeric Errors
Publication date:
03/04/2026
Last modified:
03/04/2026
Description
A vulnerability was identified in NASA cFS up to 7.0.0 on 32-bit. Affected is the function CFE_TBL_ValidateCodecLoadSize of the file cfe/modules/tbl/fsw/src/cfe_tbl_passthru_codec.c. The manipulation leads to integer overflow. The complexity of an attack is rather high. The exploitability is told to be difficult. A fix is planned for the upcoming version milestone of the project.
Impact
Base Score 4.0
2.10
Severity 4.0
LOW
Base Score 3.x
4.60
Severity 3.x
MEDIUM
Base Score 2.0
4.00
Severity 2.0
MEDIUM



