CVE-2026-48139: NULL pointer dereference vulnerability in NI grpc-device data moniker service
There is a NULL pointer dereference vulnerability in NI grpc-device in the data moniker service that may allow an attacker to cause a denial of service by triggering a crash. Successful exploitation requires an attacker to provide an unknown value to the data moniker service. This affects NI grpc-device 2.17.0 and prior versions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48139?
CVE-2026-48139 has a high severity score of 7.5.
How can I mitigate the risks associated with CVE-2026-48139?
To mitigate CVE-2026-48139, ensure that the National Instruments grpc-device software is updated to the latest version that addresses this vulnerability.
What type of impact does CVE-2026-48139 have?
CVE-2026-48139 may lead to a denial of service, causing the application to crash.
What software is affected by CVE-2026-48139?
CVE-2026-48139 affects the National Instruments grpc-device software.
What is the nature of the vulnerability in CVE-2026-48139?
CVE-2026-48139 is a NULL pointer dereference vulnerability in the data moniker service.