PT-2026-30197 · Nasa+1 · Cfs+2

·

CVE-2026-5473

·

Published

2026-04-03

·

Updated

2026-04-30

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NASA cFS versions prior to 7.0.0
Description A deserialization issue exists in the Pickle Module within the pickle.load() function. This flaw allows for manipulation through local access, although the attack requires a high level of complexity and is considered difficult to execute.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting the use of the pickle.load() function in the Pickle Module to minimize the risk of exploitation.

Exploit

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5473

Affected Products

Cfs
Cfe
Core Flight System