Vendor
Integer Underflow Vulnerability in NASA cFS cFE Software Bus
1 CVEAn integer underflow vulnerability in the CFE_SB_GetUserDataLength function of the NASA cFS cFE Software Bus (up to version 7.0.1) allows remote attackers to trigger memory corruption via manipulated message size arguments.
Remote Buffer Overflow in NASA Trick JSONVariableServer
1 TTP 1 CVECVE-2026-82478 is a stack-based buffer overflow in the NASA Trick simulation environment (version 19.6.0) that enables remote attackers to trigger memory corruption via the TCP Socket Handler.
Unauthenticated API Access in AMMOS Instrument Toolkit DSN Interface
1 TTP 1 CVEThe AMMOS Instrument Toolkit (AIT) DSN Interface prior to version 2.2.2 contains a missing authentication vulnerability in the Space Link Extension interface manager, allowing unauthenticated attackers to invoke sensitive API routes.
Authentication Bypass in AMMOS Instrument Toolkit GUI
1 TTP 1 CVEThe AMMOS Instrument Toolkit (AIT) GUI before version 2.5.1 allows unauthenticated attackers to bypass credential checks to establish sessions and issue arbitrary spacecraft commands.
NASA Core Flight System Health & Safety Application Denial-of-Service Vulnerability
1 TTPA high-severity denial-of-service vulnerability, CVE-2026-15352, affects NASA Core Flight System (cFS) Health & Safety (HS) Application versions prior to v7.0.1, allowing an unauthenticated attacker to crash the application via a crafted Housekeeping Telemetry request, leading to service disruption in critical infrastructure sectors like Transportation Systems.