VYPR

Nav2

by Opennav

CVEs (5)

  • CVE-2024-25197MedFeb 20, 2024
    risk 0.42cvss 6.5epss 0.01

    Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a NULL pointer dereference via the isCurrent() function at /src/layered_costmap.cpp.

  • CVE-2026-26011CriFeb 12, 2026
    risk 0.00cvss 9.8epss 0.01

    navigation2 is a ROS 2 Navigation Framework and System. In 1.3.11 and earlier, a critical heap out-of-bounds write vulnerability exists in Nav2 AMCL's particle filter clustering logic. By publishing a single crafted geometry_msgs/PoseWithCovarianceStamped message with extreme…

  • CVE-2024-25199HigFeb 20, 2024
    risk 0.00cvss 8.1epss 0.01

    Inappropriate pointer order of map_sub_ and map_free(map_) (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions leads to a use-after-free.

  • CVE-2024-25198CriFeb 20, 2024
    risk 0.00cvss 9.1epss 0.01

    Inappropriate pointer order of laser_scan_filter_.reset() and tf_listener_.reset() (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions leads to a use-after-free.

  • CVE-2024-25196LowFeb 20, 2024
    risk 0.00cvss 3.3epss 0.00

    Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_controller process. This vulnerability is triggerd via sending a crafted .yaml file.