CVE-2026-32708 is a high-severity stack overflow vulnerability affecting PX4 autopilot versions prior to 1.17.0-rc2, specifically within the Zenoh uORB subscriber component. Rated 8.0 HIGH (CVSS:3.1), it allows a remote Zenoh publisher with low privileges on an adjacent network to force an unbounded stack allocation and copy, resulting in a denial-of-service crash of the Zenoh bridge task and potential impact to confidentiality and integrity. Although no public exploits are currently available and it is not in the KEV catalog, the vulnerability is listed on the Hot List as "Active" and has generated some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.17.0CPE matchmatch criteria | cpe:2.3:a:dronecode:px4_drone_autopilot:*:*:*:*:*:*:*:* | ||
1.17.0CPE matchmatch criteria | cpe:2.3:a:dronecode:px4_drone_autopilot:1.17.0:alpha1:*:*:*:*:*:* | ||
1.17.0CPE matchmatch criteria | cpe:2.3:a:dronecode:px4_drone_autopilot:1.17.0:beta1:*:*:*:*:*:* | ||
1.17.0CPE matchmatch criteria | cpe:2.3:a:dronecode:px4_drone_autopilot:1.17.0:rc1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.