CVE-2026-53985 Details
Description
Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vulnerability in the Socket.IO server's service_control event handler that allows any unauthenticated network peer to forcibly terminate the ground-station process by sending a single restart_service command. Attackers can connect to the Socket.IO server on port 7000 without credentials due to disabled authentication enforcement and a wildcard CORS policy, then emit the service_control event to terminate all active satellite-tracking sessions, SDR recording pipelines, demodulators, decoders, and rotator controllers, with repeated triggering possible in Docker deployments to create a persistent denial-of-service condition.
A denial-of-service vulnerability has been identified in Ground Station versions prior to 0.6.0. The issue resides in the Socket.IO server's event handler for service control, where unauthenticated network peers can send a single restart_service command to forcibly terminate the Ground Station process. This disruption affects all active satellite-tracking sessions, software-defined radio (SDR) recording pipelines, demodulators, decoders, and rotator controllers. In Docker deployments, this vulnerability can be exploited repeatedly, creating a persistent denial-of-service condition.
Users can update to Ground Station version 0.6.0 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 6, 2026CISA-ADP
Assessed Aug 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/sgoudelis/ground-station | [email protected] | ProductVendor |
| https://github.com/sgoudelis/ground-station/commit/2ecde82a8814cbea18883ce023bf45cbf06172eb | [email protected] | Source CodeVendor |
| https://github.com/sgoudelis/ground-station/security/advisories/GHSA-mjp8-x6h7-229q | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| sgoudelis Ground Station | <= 0.5.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 6, 2026 | CVE Modified | CISA-ADP |
| Aug 6, 2026 | New CVE Received | [email protected] |
Volerion