VYPR
High severity7.5NVD Advisory· Published Jun 19, 2026· Updated Jun 25, 2026

CVE-2026-48138

CVE-2026-48138

Description

There is an out-of-bounds read vulnerability in the NI grpc-device streaming API due to a missing bounds check that may result in a denial of service. Successful exploitation requires an attacker to supply a specially crafted write request. This affects NI grpc-device 2.17.0 and prior versions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • cpe:2.3:a:ni:instrumentstudio:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:ni:instrumentstudio:*:*:*:*:*:*:*:*range: <=2025
    • cpe:2.3:a:ni:instrumentstudio:2026:q1:*:*:*:*:*:*
    • cpe:2.3:a:ni:instrumentstudio:2026:q2:*:*:*:*:*:*
  • cpe:2.3:a:ni:ni_grpc_device_server:*:*:*:*:*:*:*:*
    Range: <2.18.0
  • Ni/grpc-devicellm-fuzzy
    Range: <=2.17.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.