highOther

NASA Core Flight System (cFS) Health & Safety (HS) Application NULL Pointer Dereference

First seen Jul 21, 2026 · Updated Jul 21, 2026 · CVSS 7.5

icsscadadenial-of-servicenasacfscwe-476aerospacetransportation

A NULL pointer dereference vulnerability (CVE-2026-15352) in NASA's Core Flight System (cFS) Health & Safety (HS) Application allows a remote, unauthenticated attacker to crash the application via a crafted Housekeeping Telemetry request, causing a denial-of-service condition. The flaw affects versions prior to v7.0.1 and has been patched by NASA; no known public exploitation has been reported.

Technical Analysis

The vulnerability (CWE-476: NULL Pointer Dereference) resides in the HS application component of NASA's cFS flight software framework, triggered when the application processes a routine Housekeeping Telemetry request, causing a segmentation fault and application crash. The attack vector requires network access but no authentication or user interaction (CVSS 3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, score 7.5; CVSS 4.0 score 8.2), resulting solely in availability impact with no confidentiality or integrity loss. This affects embedded flight software used in spacecraft and satellite systems within the Transportation Systems critical infrastructure sector, not general IT or enterprise environments. There is no plausible impact to AI agent systems, LLM tool use, or RAG pipelines, as this is embedded aerospace flight control software unrelated to typical agent infrastructure.

Affected Systems

NASA Core Flight System (cFS) Health & Safety (HS) Application versions prior to v7.0.1

Indicators of Compromise

  • No specific IOCs published; no known public exploitation reported at this time.

Remediation Steps

  1. 1

    Update to Patched Version

    Update the NASA cFS Health & Safety (HS) Application to v7.0.1 or later, available at https://github.com/nasa/HS/releases/tag/v7.0.1.

  2. 2

    Network Segmentation

    Minimize network exposure for all control system devices, ensuring cFS-based systems are not accessible from the internet.

  3. 3

    Firewall Isolation

    Locate control system networks and remote devices behind firewalls and isolate them from business/enterprise networks.

  4. 4

    Secure Remote Access

    When remote access is required, use up-to-date VPNs and other secure remote access methods rather than direct exposure.

  5. 5

    Monitoring and Reporting

    Monitor for suspected malicious activity, follow internal incident response procedures, and report findings to CISA for tracking and correlation.

CVE / Advisory IDs

CVE-2026-15352

Industries Most Exposed

AerospaceTransportation SystemsGovernment/Space Research

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.