CVE-2026-48141 Details
Description
There is a memory leak in NI grpc-device BeginSidebandStream that may result in denial of service due to memory exhaustion. This affects NI grpc-device 2.17.0 and prior versions.
A memory leak vulnerability has been identified in the NI gRPC Device Server, specifically in the BeginSidebandStream API. This vulnerability, present in versions through 2.17.0, can lead to a denial-of-service condition by exhausting available memory.
Users are advised to upgrade to NI gRPC Device Server version 2.18.0 or later. For those using the NI Update Service, this update can be obtained through the service.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-401 | Missing Release of Memory after Effective Lifetime | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ni instrumentstudio | <= 2025 2026 q1 2026 q2 |
CPE
Remediation
| |
| ni ni grpc device server | < 2.18.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 25, 2026 | Initial Analysis | [email protected] |
| Jun 22, 2026 | CVE Modified | CISA-ADP |
| Jun 19, 2026 | New CVE Received | [email protected] |