CVE-2026-105164

A flaw has been found in NASA cFS up to 7.0.1. This issue affects the function CFE_FS_ParseInputFileNameEx of the file cfe/modules/fs/fsw/src/cfe_fs_api.c. This manipulation causes out-of-bounds read. Remote exploitation of the attack is possible. The pull request to fix this issue awaits acceptance.

  • Published Oct 4, 2026
  • CVSS 5.1 medium
  • 0.5% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-105164 at the National Vulnerability Database