Eprosima maintains a focused portfolio centered on the Fast DDS middleware platform, a publish-subscribe messaging implementation widely embedded in robotics, autonomous systems, and real-time distributed applications. Despite the narrow product scope, the vendor ranks among the more prominent in the vulnerability landscape due to the critical role DDS plays in safety-sensitive and networked embedded systems. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through memory-safety weakness classes including heap-based buffer overflows, out-of-bounds writes, and integer overflows that are characteristic of C/C++ implementations handling untrusted protocol input. The exposure footprint is compact but consequential: a single flaw in the DDS serialization or protocol layer can propagate to all downstream applications and devices that depend on the library. Defenders should track Eprosima advisories closely for deployments in autonomous vehicles, robotics platforms, and industrial control systems, and prioritize patching where DDS handles external or network-sourced messages; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Eprosima over time
Signals from CVEs in this vendor scope (29 CVEs).
29 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-67108CRITICAL eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket revocation, resulting in insecure communications and connections. | Dec 23, 2025 | 10.0 | 38 | NO | NO |
CVE-2021-38425CRITICAL eProsima Fast DDS versions prior to 2.4.0 (#2269) are susceptible to exploitation when an attacker sends a specially crafted packet to flood a target device with unwanted traffic, | May 5, 2022 | 9.1 | 31 | NO | NO |
CVE-2025-62799CRITICAL Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group
). Prior to versions 3.4.1, 3.3.1, and 2.6.11, a heap buffer ov | Feb 3, 2026 | 9.8 | 30 | NO | NO |
CVE-2025-65865HIGH An integer overflow in eProsima Fast-DDS v3.3 allows attackers to cause a Denial of Service (DoS) via a crafted input. | Dec 23, 2025 | 7.5 | 28 | NO | NO |
CVE-2023-50716CRITICAL eProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.13.0, 2.12.2, 2.11.3, 2 | Mar 6, 2024 | 9.8 | 25 | NO | NO |
CVE-2025-64438HIGH Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group
). Prior to versions 3.4.1, 3.3.1, and 2.6.11, a remotely trigg | Feb 3, 2026 | 7.5 | 24 | NO | NO |
CVE-2025-62603HIGH Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group
). ParticipantGenericMessage is the DDS Security control-messag | Feb 3, 2026 | 7.5 | 24 | NO | NO |
CVE-2025-62602HIGH Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group
). Prior to versions 3.4.1, 3.3.1, and 2.6.11, when the securit | Feb 3, 2026 | 7.5 | 24 | NO | NO |
CVE-2025-62601HIGH Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group
). Prior to versions 3.4.1, 3.3.1, and 2.6.11, when the securit | Feb 3, 2026 | 7.5 | 24 | NO | NO |
CVE-2025-62600HIGH eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to 2.6.11, 2.14.6, 3.2.4, 3.3.1, and 3.4.1, wh | Feb 3, 2026 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (29 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Eprosima.
Media articles that mention a CVE ID that affects a product developed by Eprosima — matched by CVE ID, not by vendor name.