CVE-2026-5473: NASA cFS Pickle pickle.load deserialization
A vulnerability has been found in NASA cFS up to 7.0.0. The impacted element is the function pickle.load of the component Pickle Module. Such manipulation leads to deserialization. The attack needs to be performed locally. The attack requires a high level of complexity. The exploitability is regarded as difficult. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5473?
CVE-2026-5473 is considered a high severity vulnerability due to its potential for local exploitation and risk of deserialization attacks.
How do I fix CVE-2026-5473?
To mitigate CVE-2026-5473, update to a version of NASA cFS beyond 7.0.0 where this vulnerability has been addressed.
What software is affected by CVE-2026-5473?
CVE-2026-5473 affects NASA cFS versions up to and including 7.0.0.
What kind of attack can be executed with CVE-2026-5473?
CVE-2026-5473 allows for local deserialization attacks through the vulnerable pickle.load function.
Who is responsible for the CVE-2026-5473 vulnerability?
CVE-2026-5473 was identified in the NASA cFS Pickle Module, which is maintained by NASA.