CVE-2026-48138: Out-of-bounds read vulnerability in the NI grpc-device streaming API
Published Jun 19, 2026
·Updated
There is an out-of-bounds read vulnerability in the NI grpc-device streaming API due to a missing bounds check that may result in a denial of service. Successful exploitation requires an attacker to supply a specially crafted write request. This affects NI grpc-device 2.17.0 and prior versions.
Affected Software
5 affected components
NI grpc-device<=2.17.0
NI InstrumentStudio<=2025
NI InstrumentStudio=2026-q1
NI InstrumentStudio=2026-q2
NI Ni Grpc Device Server<2.18.0
Event History
Jun 19, 2026
CVE Published
via MITRE·01:16 PM
Data Sourced
via MITRE·01:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48138?
The severity of CVE-2026-48138 is rated as high with a score of 8.7.
2
How do I fix CVE-2026-48138?
To fix CVE-2026-48138, upgrade to the latest version of NI grpc-device that resolves this vulnerability.
3
What impact does CVE-2026-48138 have on systems?
CVE-2026-48138 can lead to a denial of service due to an out-of-bounds read vulnerability.
4
Which versions of NI grpc-device are affected by CVE-2026-48138?
CVE-2026-48138 affects NI grpc-device version 2.17.0 and prior.
5
What type of attack vector is associated with CVE-2026-48138?
CVE-2026-48138 can be exploited by an attacker supplying a specially crafted write request.