Description
An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via the EGOReplanFSM::checkCollisionCallback()
Published: 2026-09-10
Score: 4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

The vulnerability lies in the EGOReplanFSM::checkCollisionCallback method of the EGO‑Planner‑v2 codebase. A crafted input causes a crash inside the collision callback, leading to an abrupt termination of the planner process. Because the planner drives vehicle motion, the crash results in a denial‑of‑service that can render the autonomous system inoperable. The weakness matches CWE‑400, an improper termination or resource termination scenario.

Affected Systems

The issue affects all releases of ZJU‑FAST‑Lab EGO‑Planner‑v2 up to commit 5c99a95880401e2599638d567abc0e240396cb42. Users running any of those versions are vulnerable until they upgrade to a revision newer than that commit. No other vendor or product is currently known to be impacted.

Risk and Exploitability

EPSS score is less than 1%, indicating a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, suggesting no documented widespread exploitation. Based on the description, the attack vector is likely an externally supplied input to the planner’s collision callback, which could be transmitted over a local network or API exposed by the vehicle. If an attacker can provide malformed data, the planner will crash, causing a service disruption. While exploitation remains uncertain, a successful denial of service would have a high impact.

Generated by OpenCVE AI on September 21, 2026 at 05:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a repository commit newer than 5c99a95880401e2599638d567abc0e240396cb42 where the checkCollisionCallback bug has been fixed.
  • Deploy a watchdog or health‑check mechanism that automatically restarts the planner process when it terminates, limiting downtime.
  • Implement defensive input validation on the data received by the collision callback to prevent malformed inputs from triggering a crash.

Generated by OpenCVE AI on September 21, 2026 at 05:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via EGOReplanFSM Collision Callback in EGO‑Planner v2

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics cvssV3_1

{'score': 4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Zju-fast-lab
Zju-fast-lab ego-planner-v2
Vendors & Products Zju-fast-lab
Zju-fast-lab ego-planner-v2

Fri, 11 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via EGOReplanFSM Collision Callback in EGO‑Planner v2

Fri, 11 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Title DoS via EGOReplanFSM CheckCollisionCallback in ZJU-FAST-Lab EGO-Planner‑v2
Weaknesses CWE-400

Fri, 11 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Title DoS via EGOReplanFSM CheckCollisionCallback in ZJU-FAST-Lab EGO-Planner‑v2
Weaknesses CWE-400

Thu, 10 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via the EGOReplanFSM::checkCollisionCallback()
References

Subscriptions

Zju-fast-lab Ego-planner-v2
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-20T00:09:24.389Z

Reserved: 2026-08-07T00:00:00.000Z

Link: CVE-2026-71642

cve-icon Vulnrichment

Updated: 2026-09-20T00:09:18.265Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T22:16:58.797

Modified: 2026-09-22T20:00:03.713

Link: CVE-2026-71642

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T05:30:07Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption