Description
An incomplete fix for CVE-2026-15352 in the NASA core Flight System
(cFS) Health and Safety (HS) application leaves a separate NULL pointer
dereference reachable in versions through 7.0.1. An attacker who can
trigger the affected command under specific conditions could cause the
HS application to crash, resulting in a denial-of-service condition and
processor reset.
Published: 2026-07-30
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An incomplete fix for a prior cFS HS vulnerability leaves a NULL pointer dereference reachable in all versions up to 7.0.1. When an attacker can trigger a specific command under the conditions described, the Health & Safety application will crash, causing a denial‑of‑service that can force the flight computer to reset. The flaw is a classic null‑pointer dereference (CWE-476) and does not directly affect confidentiality, but the crash may disrupt mission‑critical operations.

Affected Systems

The affected product is the NASA Core Flight System (cFS) Health & Safety (HS) Application. All installed instances running version 7.0.1 or earlier are at risk. No other vendors or product lines are listed as affected.

Risk and Exploitability

The CVSS score of 8.2 indicates a high severity vulnerability. EPSS is < 1%, indicating a very low likelihood of exploitation. The vulnerability does not list a KEV status. Because the flaw is triggered by a specific command, the attack vector is likely local or internal; however, if the command interface is exposed over a network, a remote attacker could also succeed. NASA has issued an official workaround while a formal patch is under development.

Generated by OpenCVE AI on August 2, 2026 at 04:55 UTC.

Remediation

Vendor Workaround

NASA reports that an official fix is currently under development and is expected to be included in a future software release. As an interim mitigation, users can update their HS app from the HS repo ( https://github.com/nasa/HS ) to the latest dev branch. The fix is in the dev branch starting at commit 828855f971db4b6714367ed0a970f52dbeab2965


OpenCVE Recommended Actions

  • Update the HS application to the latest dev branch on GitHub (https://github.com/nasa/HS) that includes the fix starting at commit 828855f971db4b6714367ed0a970f52dbeab2965.
  • Disable or restrict the command that can trigger the NULL pointer dereference until the fix is applied. This limits the attack surface exposed to users or external systems.
  • Maintain awareness of NASA’s future release that will contain a permanent fix and transition to a stable release as soon as it is available.

Generated by OpenCVE AI on August 2, 2026 at 04:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Nasa
Nasa core Flight System (cfs) Health & Safety (hs) Application
Vendors & Products Nasa
Nasa core Flight System (cfs) Health & Safety (hs) Application

Fri, 31 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a separate NULL pointer dereference reachable in versions through 7.0.1. An attacker who can trigger the affected command under specific conditions could cause the HS application to crash, resulting in a denial-of-service condition and processor reset.
Title NASA Core Flight System (cFS) Health & Safety (HS) Application NULL Pointer Dereference
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Nasa Core Flight System (cfs) Health & Safety (hs) Application
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-31T15:41:27.652Z

Reserved: 2026-07-28T14:10:13.503Z

Link: CVE-2026-18064

cve-icon Vulnrichment

Updated: 2026-07-31T15:41:21.938Z

cve-icon NVD

Status : Received

Published: 2026-07-30T22:16:54.790

Modified: 2026-07-31T16:17:05.247

Link: CVE-2026-18064

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:34:25Z

Weaknesses