CVE-2026-38891 Details
Description
An improper input validation in the gazebo_ros_diff_drive.cpp component of gazebo_plugins v3.9.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted geometry_msgs::Twist message.
A denial-of-service vulnerability has been identified in the Gazebo ROS Diff Drive plugin, version 3.9.0, within the gazebo_ros_diff_drive component. The issue arises from improper input validation, allowing attackers to send crafted geometry_msgs::Twist messages that bypass validation checks. These malformed messages can disrupt motion control and odometry processes, potentially causing erratic robot movements and inaccurate odometry data.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 1, 2026CISA-ADP
Assessed Jul 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/REYu6/ROS-vul/blob/main/Gazebo%20CVE/260328211736.mp4 | [email protected] | |
| https://github.com/REYu6/ROS-vul/blob/main/Gazebo%20CVE/gazebo_ros_diff_drive.md | [email protected] | ExploitTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| gazebo_ros_pkgs | 3.9.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 2, 2026 | CVE Modified | CISA-ADP |
| Jul 1, 2026 | New CVE Received | [email protected] |
Volerion