CVE-2026-67973 Details
Description
An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs.
A denial-of-service vulnerability has been identified in NASA's Core Flight System (cFS) version 7.0.1. The issue arises in the CFDP (Consultative Committee for Space Data Systems File Delivery Protocol) receive path, where completed transactions are not properly removed from the transaction lookup structure. Instead, they are only transitioned to a hold state. This flaw allows an attacker to replay final CFDP Protocol Data Units (PDUs) of the same transaction, causing resource exhaustion by keeping the transaction active and delaying its normal timeout. The vulnerability can be exploited by injecting or replaying CFDP PDUs, particularly final ones, to manipulate the transaction state and consume system resources.
No specific remediation is provided, but the issue could be addressed by removing completed transactions from the lookup structure or by implementing stricter replay handling for final PDUs.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/nasa/cFS/issues/1075 | CISA-ADP | |
| https://github.com/nasa/cFS | [email protected] | |
| https://github.com/nasa/cFS/issues/1075 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | CISA-ADP |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 5, 2026 | CVE Modified | CISA-ADP |
| Aug 3, 2026 | New CVE Received | [email protected] |