NASA Core Flight System (cFS) Health & Safety (HS) Application
Summary
NASA's Core Flight System (cFS) Health & Safety (HS) Application versions up to v7.0.1 are affected by a NULL pointer dereference vulnerability (CVE-2026-18064). Successful exploitation can lead to a denial-of-service condition and processor reset.
IFF Assessment
This vulnerability allows an attacker to cause a denial-of-service, disrupting critical systems.
Severity
The CVSS score of 7.5 indicates a High severity vulnerability. It is primarily due to the potential for a denial-of-service condition, which could lead to processor resets, impacting the availability of critical transportation systems.
Defender Context
This vulnerability in NASA's Core Flight System affects critical infrastructure, specifically transportation systems. Defenders should monitor for exploitation attempts and ensure systems are updated to the latest dev branch of the HS application as an interim mitigation while awaiting an official fix.