CVE-2026-26011
Last modified
CVE-2026-26011 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. navigation2 is a ROS 2 Navigation Framework and System. In 1.3.11 and earlier, a critical heap out-of-bounds write vulnerability exists in Nav2 AMCL's particle filter clustering logic. EPSS estimates a 0.52% chance of exploitation in the next 30 days.
Description
navigation2 is a ROS 2 Navigation Framework and System. In 1.3.11 and earlier, a critical heap out-of-bounds write vulnerability exists in Nav2 AMCL's particle filter clustering logic. By publishing a single crafted geometry_msgs/PoseWithCovarianceStamped message with extreme covariance values to the /initialpose topic, an unauthenticated attacker on the same ROS 2 DDS domain can trigger a negative index write (set->clusters[-1]) into heap memory preceding the allocated buffer. In Release builds, the sole boundary check (assert) is compiled out, leaving zero runtime protection. This primitive allows controlled corruption of the heap chunk metadata(at least the size of the heap chunk where the set->clusters is in is controllable by the attacker), potentially leading to further exploitation. At minimum, it provides a reliable single-packet denial of service that kills localization and halts all navigation.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Opennav | Nav2 | <= 1.3.11 |
References
- https://github.com/ros-navigation/navigation2/security/advisories/GHSA-mgj5-g2p6-gc5xExploit, Vendor Advisory
- https://github.com/ros-navigation/navigation2/security/advisories/GHSA-mgj5-g2p6-gc5xExploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-26011?
How severe is CVE-2026-26011?
How do I fix CVE-2026-26011?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-26006AutoGPT is a platform that allows users to create, deploy, a…6.5
- CVE-2026-26007cryptography is a package designed to expose cryptographic p…6.5
- CVE-2026-26008EVerest is an EV charging software stack. Versions prior to …7.5
- CVE-2026-26009Catalyst is a platform built for enterprise game server host…9.9
- CVE-2026-2601GitLab has remediated an issue in GitLab EE affecting all ve…4.3
- CVE-2026-26010OpenMetadata is a unified metadata platform. Prior to 1.11.8…7.6
- CVE-2026-26012vaultwarden is an unofficial Bitwarden compatible server wri…6.5
- CVE-2026-26013LangChain is a framework for building agents and LLM-powered…3.7
- CVE-2026-26014Pion DTLS is a Go implementation of Datagram Transport Layer…5.9
- CVE-2026-26015DocsGPT is a GPT-powered chat for documentation. From versio…9.8
- CVE-2026-26016Wings is the server control plane for Pterodactyl, a free, o…8.1
- CVE-2026-26017CoreDNS is a DNS server that chains plugins. Prior to versio…6.3
Are you affected by CVE-2026-26011?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
