<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Trick (19.6.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/trick-19.6.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 30 Aug 2026 07:09:00 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/trick-19.6.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Buffer Overflow in NASA Trick JSONVariableServer</title><link>https://feed.craftedsignal.io/briefs/2026-08-cve-2026-82478-nasa-trick/</link><pubDate>Sun, 30 Aug 2026 07:09:00 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-cve-2026-82478-nasa-trick/</guid><description>CVE-2026-82478 is a stack-based buffer overflow in the NASA Trick simulation environment (version 19.6.0) that enables remote attackers to trigger memory corruption via the TCP Socket Handler.</description><content:encoded><![CDATA[<p>NASA Trick version 19.6.0 contains a stack-based buffer overflow vulnerability within the <code>JSONVariableServerThread::parse_request</code> function, located in <code>trick_source/sim_services/JSONVariableServer/JSONVariableServerThread.cpp</code>. This component acts as a TCP socket handler for the simulation environment. An attacker can trigger this vulnerability by sending a maliciously crafted packet to the JSONVariableServer. Because the vulnerability exists within the request parsing logic, it is reachable by remote, unauthenticated attackers who have network access to the simulation server. Successful exploitation may lead to a denial-of-service condition via application crash or potentially arbitrary code execution in the context of the running simulation. NASA has not provided a response to this vulnerability disclosure, and no patch is currently available for version 19.6.0.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability affects instances of the NASA Trick simulation framework version 19.6.0 that expose the JSONVariableServer over a TCP socket. If successfully exploited, the primary impact is service instability or a complete crash of the simulation server. In environments where the Trick server runs with high-privilege execution, there is a risk of arbitrary code execution, which could allow an attacker to gain control over the simulation environment and access sensitive data processed within the simulation pipeline.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Monitor network traffic destined for the Trick JSONVariableServer TCP ports for malformed or unusually large payloads that may indicate buffer overflow attempts.</li>
<li>Restrict network access to the Trick JSONVariableServer to authorized IP ranges only, using network segmentation or firewall rules, until an official patch is released by NASA.</li>
<li>Audit simulation server logs for sudden service restarts or anomalous process terminations that could indicate exploitation attempts causing service crashes.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>cve</category><category>vulnerability</category><category>remote-code-execution</category><category>nasa-trick</category></item></channel></rss>