CVE-2026-105164EPSS p43.7%
CVE-2026-105164CVE-2026-105164
Description
A flaw has been found in NASA cFS up to 7.0.1. This issue affects the function CFE_FS_ParseInputFileNameEx of the file cfe/modules/fs/fsw/src/cfe_fs_api.c. This manipulation causes out-of-bounds read. Remote exploitation of the attack is possible. The pull request to fix this issue awaits acceptance.
Scoring
| CVSS | 2.7 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L |
| EPSS | 0.54% probability of exploitation · percentile 43.7% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-06 |