CVE-2026-82478: NASA Trick TCP Socket JSONVariableServerThread.cpp parse_request stack-based overflow
A vulnerability was determined in NASA Trick 19.6.0. This issue affects the function JSONVariableServerThread::parserequest of the file tricksource/simservices/JSONVariableServer/JSONVariableServerThread.cpp of the component TCP Socket Handler. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Systems running NASA Trick 19.6.0 with the TCP Socket Handler and its JSONVariableServer component reachable by an attacker are exposed. The vulnerability can be exploited remotely.
Does exploitation require authentication or user interaction?
No authentication or user interaction is indicated by the provided CVSS vector. The vector also indicates low attack complexity and network attack access.
What is the potential impact of successful exploitation?
The reported impact includes low confidentiality, integrity, and availability effects. The underlying flaw is a stack-based buffer overflow in JSONVariableServerThread::parse_request.
Is a vendor fix or workaround available?
No fix or workaround is provided in the available data. The vendor was contacted about the disclosure but reportedly did not respond.