Ros is a robotics middleware framework with a narrow product portfolio but significant presence in autonomous systems and research deployments where its libraries underpin real-time control and inter-process communication. Vulnerabilities affecting the vendor skew strongly toward critical severity and cluster in foundational packages such as ros-comm and sros2 around memory-safety and information-disclosure weaknesses including buffer overflows, integer wraparound, and exposure of sensitive data in unencrypted communications—issues inherent to C++ middleware handling untrusted network input in safety-critical environments. Defenders deploying Ros in production systems should prioritize patching high-severity disclosures and audit network isolation of affected nodes; live severity and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ros over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-13566CRITICAL An issue was discovered in the ROS communications-related packages (aka ros_comm or ros-melodic-ros-comm) through 1.14.3. A buffer overflow allows attackers to cause a denial of se | Nov 22, 2019 | 9.8 | 31 | NO | NO |
CVE-2020-16124CRITICAL Integer Overflow or Wraparound vulnerability in the XML RPC library of OpenRobotics ros_comm communications packages allows unauthenticated network traffic to cause unexpected beha | Oct 13, 2020 | 9.8 | 30 | NO | NO |
CVE-2019-13445CRITICAL An issue was discovered in the ROS communications-related packages (aka ros_comm or ros-melodic-ros-comm) through 1.14.3. parseOptions() in tools/rosbag/src/record.cpp has an integ | Dec 30, 2019 | 9.8 | 29 | NO | NO |
CVE-2021-37146HIGH An infinite loop in Open Robotics ros_comm XMLRPC server in ROS Melodic through 1.4.11 and ROS Noetic through1.15.11 allows remote attackers to cause a Denial of Service in ros_com | Sep 28, 2021 | 7.5 | 25 | NO | NO |
CVE-2019-13465HIGH An issue was discovered in the ROS communications-related packages (aka ros_comm or ros-melodic-ros-comm) through 1.14.3. ROS_ASSERT_MSG only works when ROS_ASSERT_ENABLED is defin | Dec 30, 2019 | 8.6 | 25 | NO | NO |
CVE-2019-19625MEDIUM SROS 2 0.8.1 (which provides the tools that generate and distribute keys for Robot Operating System 2 and uses the underlying security plugins of DDS from ROS 2) leaks node informa | Dec 6, 2019 | 5.3 | 19 | NO | NO |
CVE-2019-19627MEDIUM SROS 2 0.8.1 (after CVE-2019-19625 is mitigated) leaks ROS 2 node-related information regardless of the rtps_protection_kind configuration. (SROS2 provides the tools to generate an | Dec 6, 2019 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ros.
Media articles that mention a CVE ID that affects a product developed by Ros — matched by CVE ID, not by vendor name.