Medium severity4.5NVD Advisory· Published Apr 3, 2026· Updated Apr 30, 2026
CVE-2026-5473
CVE-2026-5473
Description
A vulnerability has been found in NASA cFS up to 7.0.0. The impacted element is the function pickle.load of the component Pickle Module. Such manipulation leads to deserialization. The attack needs to be performed locally. The attack requires a high level of complexity. The exploitability is regarded as difficult. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- vuldb.com/submit/781949nvdThird Party AdvisoryVDB Entry
- vuldb.com/vuln/355077nvdThird Party AdvisoryVDB Entry
- github.com/nasa/cFS/issues/951nvdIssue Tracking
- vuldb.com/vuln/355077/ctinvdPermissions RequiredVDB Entry
News mentions
0No linked articles in our index yet.