eProsima / Fast-DDS
23 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-22591 | Fast DDS DDSSQLFilter Recursive Parser Stack Exhaustion (Remote DoS) | HIGH | 7.5 | Sep 9, 2026 |
| CVE-2026-22590 | Fast-DDS Discovery Server: Out-of-Bounds Read & Heap Memory Disclosure via DATA_FRAG sampleSize / fragmentsInSubmessage | CRITICAL | 9.1 | Sep 9, 2026 |
| CVE-2025-64438 | Fast-DDS: Unbounded GAP range triggers OOM DoS under RELIABLE QoS | LOW | 1.7 | Feb 3, 2026 |
| CVE-2025-64098 | FastDDS has Out-of-memory in readOctetVector via Manipulated DATA Submessage when DDS Security is enabled | LOW | 1.7 | Feb 3, 2026 |
| CVE-2025-62799 | FastDDS's heap buffer overflow in RTPS DATA_FRAG enables unauthenticated DoS (potential RCE) | HIGH | 7.2 | Feb 3, 2026 |
| CVE-2025-62603 | FastDDS has Out-of-memory while parsing GenericMessage when DDS Security is enabled | LOW | 1.7 | Feb 3, 2026 |
| CVE-2025-62602 | FastDDS has heap buffer overflow in readData via Manipulated DATA Submessage when DDS Security is enabled | LOW | 1.7 | Feb 3, 2026 |
| CVE-2025-62601 | FastDDS has heap buffer overflow in readString via Manipulated DATA Submessage when DDS Security is enabled | LOW | 1.7 | Feb 3, 2026 |
| CVE-2025-62600 | eprosima Fast DDS affected by Out-of-Memory in readBinaryPropertySeq via Manipulated DATA Submessage when DDS Security is enabled | HIGH | 8.6 | Feb 3, 2026 |
| CVE-2025-62599 | eprosima Fast DDS affected by Out-of-Memory in readPropertySeq via Manipulated DATA Submessage when DDS Security is enabled | HIGH | 8.6 | Feb 3, 2026 |
| CVE-2025-24807 | Fast DDS does not verify Permissions CA | MEDIUM | 4.5 | Feb 11, 2025 |
| CVE-2024-30259 | FastDDS heap buffer overflow when publisher sends malformed packet | HIGH | 8.2 | May 13, 2024 |
| CVE-2024-30258 | FastDDS crash when publisher send malformed packet | HIGH | 8.2 | May 13, 2024 |
| CVE-2024-28231 | Manipulated DATA Submessage causes a heap-buffer-overflow error | CRITICAL | 9.7 | Mar 20, 2024 |
| CVE-2023-50716 | Invalid DATA_FRAG Submessage causes a bad-free error | CRITICAL | 9.8 | Mar 6, 2024 |
| CVE-2023-50257 | Disconnect Vulnerability in RTPS Packets Used by SROS2 | CRITICAL | 9.7 | Feb 19, 2024 |
| CVE-2023-42459 | Malformed DATA submessage leads to bad-free error in Fast-DDS | HIGH | 8.6 | Oct 16, 2023 |
| CVE-2023-39949 | Improper validation of sequence numbers leading to remotely reachable assertion failure | HIGH | 7.5 | Aug 11, 2023 |
| CVE-2023-39948 | Uncaught fastcdr exception (Unexpected CDR type received) crashing fastdds | HIGH | 7.5 | Aug 11, 2023 |
| CVE-2023-39947 | Another heap overflow in push_back_helper | HIGH | 8.2 | Aug 11, 2023 |
| CVE-2023-39946 | Heap overflow in push_back_helper due to a CDR message | HIGH | 8.2 | Aug 11, 2023 |
| CVE-2023-39945 | Malformed serialized data in a data submessage leads to unhandled exception | HIGH | 8.2 | Aug 11, 2023 |
| CVE-2023-39534 | Malformed GAP submessage triggers assertion failure | HIGH | 7.5 | Aug 11, 2023 |
Showing 1 to 23 of 23 CVEs