CVE-2026-9143: Incorrect Conversion between Numeric Types in NI grpc-device due to missing range checks in CodeGen
Published Jun 19, 2026
·Updated
There is an incorrect conversion between numeric types vulnerability in NI grpc-device due to missing range checks in CodeGen. This may silently discard high bits if a size value exceeded the target type's range. This affects NI grpc-device 2.17.0 and prior versions.
Affected Software
5 affected components
National Instruments NI grpc-device<=2.17.0
NI InstrumentStudio<=2025
NI InstrumentStudio=2026-q1
NI InstrumentStudio=2026-q2
NI Ni Grpc Device Server<2.18.0
Event History
Jun 19, 2026
CVE Published
via MITRE·01:48 PM
Data Sourced
via MITRE·01:48 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeaknessAffected Software
Aug 12, 58454
Event
via FIRST·11:23 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-9143?
The severity of CVE-2026-9143 is rated low, with a score of 3.7.
2
How do I fix CVE-2026-9143?
To fix CVE-2026-9143, update to the latest version of NI grpc-device, which addresses the missing range checks.
3
What impact does CVE-2026-9143 have on system security?
CVE-2026-9143 may lead to silent data corruption by discarding high bits when numeric values exceed the target type's range.
4
Which versions of NI grpc-device are affected by CVE-2026-9143?
CVE-2026-9143 affects NI grpc-device version 2.17.0 and prior versions.
5
What type of vulnerability is CVE-2026-9143?
CVE-2026-9143 is classified as an incorrect conversion between numeric types due to missing range checks.