Description
A vulnerability exists in the Health & Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the application to crash via segmentation fault when processing a routine Housekeeping Telemetry request, leading to denial of service.
Published: 2026-07-16
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a NULL pointer dereference that causes a segmentation fault when a routine Housekeeping Telemetry request is processed. The crash brings down the Health & Safety application, resulting in loss of telemetry and availability for other components that depend on it. It does not expose data or allow code execution, but it produces a denial of service.

Affected Systems

All installations of NASA's Core Flight System Health & Safety application that are running a version earlier than 7.0.1 are affected. The patch is available in the NASA GitHub HS repository as version 7.0.1, which updates the HS component.

Risk and Exploitability

The CVSS score of 8.2 indicates high severity. The EPSS score of less than 1% suggests that exploitation is considered unlikely at this time, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves an attacker injecting a malformed Housekeeping Telemetry packet that triggers the null dereference; external exposure or network access details are not provided.

Generated by OpenCVE AI on July 31, 2026 at 01:22 UTC.

Remediation

Vendor Solution

NASA recommends users update to v7.0.1  https://github.com/nasa/HS/releases/tag/v7.0.1


OpenCVE Recommended Actions

  • Update the Health & Safety application to version 7.0.1 from the NASA GitHub repository and restart the cFS system to load the new component.
  • If an immediate update is not feasible, temporarily disable the HS application’s processing of Housekeeping Telemetry requests until the patch can be applied.
  • Configure a watchdog timer to automatically restart the HS application after a crash to maintain telemetry availability.

Generated by OpenCVE AI on July 31, 2026 at 01:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Nasa
Nasa core Flight System
Vendors & Products Nasa
Nasa core Flight System

Fri, 17 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description A vulnerability exists in the Health & Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the application to crash via segmentation fault when processing a routine Housekeeping Telemetry request, leading to denial of service. A vulnerability exists in the Health & Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the application to crash via segmentation fault when processing a routine Housekeeping Telemetry request, leading to denial of service.

Thu, 16 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Description A vulnerability exists in the Health & Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the application to crash via segmentation fault when processing a routine Housekeeping Telemetry request, leading to denial of service.
Title NASA Core Flight System (cFS) Health & Safety (HS) Application NULL Pointer Dereference
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Nasa Core Flight System
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-17T13:26:28.783Z

Reserved: 2026-07-09T22:03:49.631Z

Link: CVE-2026-15352

cve-icon Vulnrichment

Updated: 2026-07-17T13:26:17.886Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T01:30:05Z

Weaknesses