PT-2026-30197 · Nasa · Cfs+1

0Rbitingzer0

·

Published

2026-04-03

·

Updated

2026-04-30

·

CVE-2026-5473

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NASA cFS versions prior to 7.0.0
Description A deserialization issue exists in the Pickle Module within the pickle.load() function. This flaw allows for manipulation through local access, although the attack requires a high level of complexity and is considered difficult to execute.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting the use of the pickle.load() function in the Pickle Module to minimize the risk of exploitation.

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2026-5473

Affected Products

Cfs
Core Flight System