Fast Dds
eProsima · 28 CVEs
Fast-DDS: Unbounded GAP range triggers OOM DoS under RELIABLE QoS
Feb 3, 2026
FastDDS has Out-of-memory in readOctetVector via Manipulated DATA Submessage when DDS Security is enabled
Feb 3, 2026
FastDDS's heap buffer overflow in RTPS DATA_FRAG enables unauthenticated DoS (potential RCE)
Feb 3, 2026
FastDDS has Out-of-memory while parsing GenericMessage when DDS Security is enabled
Feb 3, 2026
FastDDS has heap buffer overflow in readData via Manipulated DATA Submessage when DDS Security is enabled
Feb 3, 2026
FastDDS has heap buffer overflow in readString via Manipulated DATA Submessage when DDS Security is enabled
Feb 3, 2026
eprosima Fast DDS affected by Out-of-Memory in readBinaryPropertySeq via Manipulated DATA Submessage when DDS Security…
Feb 3, 2026
eprosima Fast DDS affected by Out-of-Memory in readPropertySeq via Manipulated DATA Submessage when DDS Security is ena…
Feb 3, 2026
eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket revocation, resulting in insecure commu…
Dec 23, 2025
An integer overflow in eProsima Fast-DDS v3.3 allows attackers to cause a Denial of Service (DoS) via a crafted input.
Dec 23, 2025
eProsima Fast-DDS v3.3 and before has an infinite loop vulnerability caused by integer overflow in the Time_t:: fractio…
Nov 18, 2025
Fast DDS does not verify Permissions CA
Feb 11, 2025
FastDDS heap buffer overflow when publisher sends malformed packet
May 13, 2024
FastDDS crash when publisher send malformed packet
May 13, 2024
An issue was discovered in eProsima FastDDS v.2.14.0 and before, allows a local attacker to cause a denial of service (…
Apr 11, 2024
An issue was discovered in eProsima FastDDS v.2.14.0 and before, allows a local attacker to cause a denial of service (…
Apr 11, 2024
Manipulated DATA Submessage causes a heap-buffer-overflow error
Mar 20, 2024
An issue in the HistoryQosPolicy component of FastDDS v2.12.x, v2.11.x, v2.10.x, and v2.6.x leads to a SIGABRT (signal…
Mar 19, 2024
Invalid DATA_FRAG Submessage causes a bad-free error
Mar 6, 2024
Disconnect Vulnerability in RTPS Packets Used by SROS2
Feb 19, 2024
Malformed DATA submessage leads to bad-free error in Fast-DDS
Oct 16, 2023
Improper validation of sequence numbers leading to remotely reachable assertion failure
Aug 11, 2023
Uncaught fastcdr exception (Unexpected CDR type received) crashing fastdds
Aug 11, 2023
Another heap overflow in push_back_helper
Aug 11, 2023
Heap overflow in push_back_helper due to a CDR message
Aug 11, 2023
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-64438 | Fast-DDS: Unbounded GAP range triggers OOM DoS under RELIABLE QoS | LOW | 0.61% | Feb 3, 2026 |
| CVE-2025-64098 | FastDDS has Out-of-memory in readOctetVector via Manipulated DATA Submessage when DDS Security is enabled | LOW | 0.49% | Feb 3, 2026 |
| CVE-2025-62799 | FastDDS's heap buffer overflow in RTPS DATA_FRAG enables unauthenticated DoS (potential RCE) | HIGH | 0.55% | Feb 3, 2026 |
| CVE-2025-62603 | FastDDS has Out-of-memory while parsing GenericMessage when DDS Security is enabled | LOW | 0.56% | Feb 3, 2026 |
| CVE-2025-62602 | FastDDS has heap buffer overflow in readData via Manipulated DATA Submessage when DDS Security is enabled | LOW | 0.55% | Feb 3, 2026 |
| CVE-2025-62601 | FastDDS has heap buffer overflow in readString via Manipulated DATA Submessage when DDS Security is enabled | LOW | 0.59% | Feb 3, 2026 |
| CVE-2025-62600 | eprosima Fast DDS affected by Out-of-Memory in readBinaryPropertySeq via Manipulated DATA Submessage when DDS Security is enabled | HIGH | 0.46% | Feb 3, 2026 |
| CVE-2025-62599 | eprosima Fast DDS affected by Out-of-Memory in readPropertySeq via Manipulated DATA Submessage when DDS Security is enabled | HIGH | 0.41% | Feb 3, 2026 |
| CVE-2025-67108 | eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket revocation, resulting in insecure communications and connections. | CRITICAL | 0.31% | Dec 23, 2025 |
| CVE-2025-65865 | An integer overflow in eProsima Fast-DDS v3.3 allows attackers to cause a Denial of Service (DoS) via a crafted input. | HIGH | 0.40% | Dec 23, 2025 |
| CVE-2025-63829 | eProsima Fast-DDS v3.3 and before has an infinite loop vulnerability caused by integer overflow in the Time_t:: fraction() function. | HIGH | 0.32% | Nov 18, 2025 |
| CVE-2025-24807 | Fast DDS does not verify Permissions CA | MEDIUM | 0.20% | Feb 11, 2025 |
| CVE-2024-30259 | FastDDS heap buffer overflow when publisher sends malformed packet | HIGH | 0.87% | May 13, 2024 |
| CVE-2024-30258 | FastDDS crash when publisher send malformed packet | HIGH | 0.79% | May 13, 2024 |
| CVE-2024-30917 | An issue was discovered in eProsima FastDDS v.2.14.0 and before, allows a local attacker to cause a denial of service (DoS) and obtain sensitive information vi… | MEDIUM | 0.22% | Apr 11, 2024 |
| CVE-2024-30916 | An issue was discovered in eProsima FastDDS v.2.14.0 and before, allows a local attacker to cause a denial of service (DoS) and obtain sensitive information vi… | HIGH | 0.24% | Apr 11, 2024 |
| CVE-2024-28231 | Manipulated DATA Submessage causes a heap-buffer-overflow error | CRITICAL | 0.94% | Mar 20, 2024 |
| CVE-2024-26369 | An issue in the HistoryQosPolicy component of FastDDS v2.12.x, v2.11.x, v2.10.x, and v2.6.x leads to a SIGABRT (signal abort) upon receiving DataWriter's data. | HIGH | 0.62% | Mar 19, 2024 |
| CVE-2023-50716 | Invalid DATA_FRAG Submessage causes a bad-free error | CRITICAL | 0.72% | Mar 6, 2024 |
| CVE-2023-50257 | Disconnect Vulnerability in RTPS Packets Used by SROS2 | CRITICAL | 0.48% | Feb 19, 2024 |
| CVE-2023-42459 | Malformed DATA submessage leads to bad-free error in Fast-DDS | HIGH | 0.83% | Oct 16, 2023 |
| CVE-2023-39949 | Improper validation of sequence numbers leading to remotely reachable assertion failure | HIGH | 1.04% | Aug 11, 2023 |
| CVE-2023-39948 | Uncaught fastcdr exception (Unexpected CDR type received) crashing fastdds | HIGH | 1.04% | Aug 11, 2023 |
| CVE-2023-39947 | Another heap overflow in push_back_helper | HIGH | 0.96% | Aug 11, 2023 |
| CVE-2023-39946 | Heap overflow in push_back_helper due to a CDR message | HIGH | 0.89% | Aug 11, 2023 |
Showing 1 to 25 of 28 CVEs