Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-41144

31
FAUCET Score

OVERVIEW CVE-2026-41144 is a critical logic vulnerability in F Prime (F Prime) framework versions prior to 4.2.0, which is used for developing spaceflight and embedded software applications. The vulnerability stems from an integer overflow in bounds checking combined with insufficient path sanitization, allowing attackers to write arbitrary data to any file location. SEVERITY The vulnerability has a network attack vector with low complexity and requires no authentication or user interaction, making it highly accessible to potential attackers. Two distinct flaws converge to enable exploitation: first, a U32 integer overflow in the bounds check (byteOffset + dataSize > fileSize) that wraps around on overflow, and second, the complete absence of destination file path validation. The combined impact is arbitrary file write capabilities at any offset, enabling remote code execution on affected embedded targets. While the CVSS score indicates informational severity, this appears inconsistent with the actual RCE impact and should be treated as a critical finding. EXPLOITATION STATUS The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no public exploit code is confirmed available. However, it appears on the Active Hot List, indicating active community monitoring and concern. The low EPSS score (0.001) suggests limited current exploit prevalence, but the straightforward nature of the vulnerability and its RCE potential warrant immediate patching of F Prime deployments, particularly those in critical spaceflight and embedded systems environments. Patch version 4.2.0 is available with no documented workarounds.

Impacted Technologies

VendorProductVersion(s)CPE
4.1.1CPE matchmatch criteria
cpe:2.3:a:nasa:fprime:4.1.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

0.0NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
0.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.43%
Probability of exploitation in next 30 days
EPSS Percentile
35.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0043 is in the 12th percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

github.com / nasa/fprime/commit/cacdd555456bd83ab395b521d56c0330470ea798
Patch
github.com / nasa/fprime/security/advisories/GHSA-qmvv-rxh4-ccqh
PatchVendor Advisory