Opennav maintains a focused autonomous-navigation software stack centered on the Nav2 platform, which is deployed across robotics and autonomous-system implementations. Vulnerabilities in this product cluster around memory-safety issues including use-after-free conditions, buffer overflows, heap-based buffer overflows, NULL-pointer dereferences, and out-of-bounds writes, reflecting the low-level C++ implementations typical of real-time navigation and sensor-processing codebases. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opennav over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-26011CRITICAL navigation2 is a ROS 2 Navigation Framework and System. In 1.3.11 and earlier, a critical heap out-of-bounds write vulnerability exists in Nav2 AMCL's particle filter clustering lo | Feb 12, 2026 | 9.8 | 31 | NO | NO |
CVE-2024-25199HIGH Inappropriate pointer order of map_sub_ and map_free(map_) (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions leads to a use-after-free. | Feb 20, 2024 | 8.1 | 23 | NO | NO |
CVE-2024-25198CRITICAL Inappropriate pointer order of laser_scan_filter_.reset() and tf_listener_.reset() (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions lead | Feb 20, 2024 | 9.1 | 22 | NO | NO |
CVE-2024-25197MEDIUM Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a NULL pointer dereference via the isCurrent() function at /src/layered_costmap | Feb 20, 2024 | 6.5 | 17 | NO | NO |
Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_controller process. This vulnerability is trigge | Feb 20, 2024 | 3.3 | 13 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opennav.
Media articles that mention a CVE ID that affects a product developed by Opennav — matched by CVE ID, not by vendor name.