Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-5476

20
FAUCET Score

CVE-2026-5476 describes an integer overflow vulnerability in the CFE_TBL_ValidateCodecLoadSize function of NASA cFS up to version 7.0.0 on 32-bit systems. This Medium severity vulnerability (CVSS 4.6) requires adjacent network access and low privileges, but has high attack complexity, resulting in low impacts to confidentiality, integrity, and availability. Exploitation is considered difficult, with no public exploit code or active exploitation observed, and community attention is minimal. A fix for this issue is planned for an upcoming version milestone of the project.

Impacted Technologies

VendorProductVersion(s)CPE
<= 7.0.0CPE matchmatch criteria
cpe:2.3:a:nasa:core_flight_system:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

2.1LOW

CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
ADJACENT
Attack Complexity
HIGH
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
LOW
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.21%
Probability of exploitation in next 30 days
EPSS Percentile
11.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0021 is in the 14th percentile among its peer group of 74 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / nasa/cFS
Product
github.com / nasa/cFS/issues/954
Issue Tracking
vuldb.com / submit/781971
Third Party AdvisoryVDB Entry
vuldb.com / vuln/355080
Third Party AdvisoryVDB Entry
vuldb.com / vuln/355080/cti
Permissions RequiredVDB Entry