Description
An issue in OpenDDS 3.33.x allows a local attacker to cause a denial of service via the verify function in the SIgnedDocument module
Published: 2026-09-08
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the SignedDocument module of OpenDDS 3.33.x. A local attacker who can execute code within the same user context can trigger a denial of service by manipulating the verify function. This flaw leads to an unhandled error condition or resource exhaustion, ultimately causing the OpenDDS service to crash or become unresponsive. The weakness exemplifies a typical denial‑of‑service bug where the application fails to validate input or manage resources safely.

Affected Systems

The affected product is OpenDDS version 3.33.x. No specific vendor or sub‑product details are provided beyond the general OpenDDS name. Users running this specific release on any platform are potentially exposed, as the Verify function is part of the core DDS implementation used for security checks.

Risk and Exploitability

The CVSS score is 6.6, but the EPSS score is < 1% and it is not listed in CISA KEV, suggesting limited public exploitation. Nevertheless, the vulnerability can be exercised locally by anyone with write or execution permissions on the system, making it a serious internal risk. An attacker could abruptly terminate the DDS service, causing a local denial of service for all clients relying on that service. The risk is compounded in environments where OpenDDS handles critical real‑time or safety‑critical data streams.

Generated by OpenCVE AI on September 10, 2026 at 03:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade OpenDDS to a version where the SignedDocument verify function has been hardened against malformed input or resource exhaustion.
  • If an upgrade is not immediately possible, isolate the OpenDDS process so that only trusted systems can invoke the verify function; restrict local permissions to prevent arbitrary execution of the vulnerable code.
  • Apply a local code correction by updating SignedDocument.cpp to include defensive checks around the verification logic, or replace the function with a patched version from the vendor’s repository.

Generated by OpenCVE AI on September 10, 2026 at 03:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 27 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Opendds
Opendds opendds
Vendors & Products Opendds
Opendds opendds

Thu, 10 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Title Local Attacker Can Trigger Denial of Service via SignedDocument Verification in OpenDDS 3.33.x

Wed, 09 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-347
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description An issue in OpenDDS 3.33.x allows a local attacker to cause a denial of service via the verify function in the SIgnedDocument module
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-09T18:43:11.404Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-52486

cve-icon Vulnrichment

Updated: 2026-09-09T18:42:53.461Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T20:17:34.920

Modified: 2026-09-09T19:17:28.233

Link: CVE-2026-52486

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T18:15:12Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature