Description
An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via the EGOReplanFSM component
Published: 2026-09-10
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Update
AI Analysis

Impact

The vulnerability resides in the EGOReplanFSM component of ZJU‑FAST‑Lab EGO‑Planner‑v2 and allows an attacker to trigger a crash or persistent failure in the planning module, leading to a loss of service availability for the affected system. The weakness enables the attacker to cause the application to become unresponsive or terminate, effectively denying legitimate users access. The impact is confined to availability, with no disclosed compromise of confidentiality or integrity.

Affected Systems

All versions of ZJU‑FAST‑Lab EGO‑Planner‑v2 up to commit 5c99a95880401e2599638d567abc0e240396cb42 are affected. The vulnerability is present in the EGOReplanFSM component across the project’s codebase, regardless of the operating environment; no specific platform restrictions are mentioned.

Risk and Exploitability

The CVE entry lists a CVSS score of 7.5 and an EPSS value of < 1%, and the vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector is remote, using the network interface(s) that the EGOReplanFSM component exposes, though the official advisory does not state this explicitly. Because the flaw can cause a denial of service, the risk is moderate to high for systems that rely on continuous operation of the planner. Exploitation would require the attacker to send crafted input or induce a state that leads the FSM to crash; no elevated privileges are required as long as the affected component is publicly reachable.

Generated by OpenCVE AI on September 21, 2026 at 05:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest commit newer than 5c99a958, which removes the resource‑exhaustion flaw in EGOReplanFSM (CWE‑400).
  • Limit the size and frequency of input requests to the EGOReplanFSM endpoint, enforcing strict validation to be updated immediately, disable or isolate the EGOReplanFSM feature from untrusted networks so it is no longer reachable.
  • Continuously monitor system logs and performance metrics for abnormal crashes or high CPU attempts.

Generated by OpenCVE AI on September 21, 2026 at 05:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 27 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Zju-fast-lab
Zju-fast-lab ego-planner-v2
Vendors & Products Zju-fast-lab
Zju-fast-lab ego-planner-v2

Mon, 21 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via EGOReplanFSM Crash in EGO‑Planner‑v2

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via EGOReplanFSM Crash in EGO‑Planner‑v2
Weaknesses CWE-400

Thu, 10 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via the EGOReplanFSM component
References

Subscriptions

Zju-fast-lab Ego-planner-v2
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T17:14:52.267Z

Reserved: 2026-08-07T00:00:00.000Z

Link: CVE-2026-71643

cve-icon Vulnrichment

Updated: 2026-09-14T17:14:35.109Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T22:16:58.940

Modified: 2026-09-22T20:00:03.713

Link: CVE-2026-71643

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T10:30:10Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption