Description
An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via the EGOReplanFSM component
Published: 2026-09-10
Score: n/a
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Immediate Update
AI Analysis

Impact

The vulnerability resides in the EGOReplanFSM component of ZJU-FAST-Lab EGO-Planner-v2 and allows an attacker to trigger a crash or persistent failure in the planning module, leading to a loss of service availability for the affected system. The weakness enables the attacker to cause the application to become unresponsive or terminate, effectively denying legitimate users access. The impact is confined to availability, with no disclosed compromise of confidentiality or integrity.

Affected Systems

All versions of ZJU-FAST-Lab EGO‑Planner‑v2 up to commit 5c99a95880401e2599638d567abc0e240396cb42 are affected. The vulnerability is present in the EGOReplanFSM component across the project’s codebase, regardless of the operating environment; no specific platform restrictions are mentioned.

Risk and Exploitability

The CVE entry does not provide a CVSS score or EPSS value, and the vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector is remote, using the network interface(s) that the EGOReplanFSM component exposes, though the official advisory does not state this explicitly. Because the flaw can cause a denial of service, the risk is moderate to high for systems that rely on continuous operation of the planner. Exploitation would require the attacker to send crafted input or induce a state that leads the FSM to crash; no elevated privileges are required as long as the affected component is publicly reachable.

Generated by OpenCVE AI on September 11, 2026 at 04:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest commit newer than 5c99a958, which removes the resource‑exhaustion flaw in EGOReplanFSM (CWE‑400).
  • Limit the size and frequency of input requests to the EGOReplanFSM endpoint, enforcing strict validation to prevent excessive resource consumption.
  • If the component cannot be updated immediately, disable or isolate the EGOReplanFSM feature from untrusted networks so it is no longer reachable.
  • Continuously monitor system logs and performance metrics for abnormal crashes or high CPU attempts.

Generated by OpenCVE AI on September 11, 2026 at 04:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via EGOReplanFSM Crash in EGO‑Planner‑v2
Weaknesses CWE-400

Thu, 10 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via the EGOReplanFSM component
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-10T21:42:32.375Z

Reserved: 2026-08-07T00:00:00.000Z

Link: CVE-2026-71643

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-10T22:16:58.940

Modified: 2026-09-10T22:16:58.940

Link: CVE-2026-71643

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T04:30:19Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption