CVE-2026-71641
nicheDenial of Service in ZJU-FAST-Lab EGO-Planner-v2 planner and trajectory server
ZJU-FAST-Lab EGO-Planner-v2 contains a CWE-400 (uncontrolled resource consumption) flaw in the interaction between the traj_server node, the poscmd_2_odom relay, and the EGOReplanFSM emergency recovery logic. Because the software is reachable over the network with low attack complexity and requires no privileges or user interaction, an attacker on a network that can reach the robot's ROS communication layer can drive these components into a resource-exhaustion or livelock condition, crashing or hanging the planning stack and causing a complete loss of trajectory command output (a serious availability problem for a flying drone, which may stop responding to planner commands). All versions up to and including commit 5c99a95880401e2599638d567abc0e240396cb42 are affected. There is no known public proof-of-concept and no evidence of exploitation in the wild.
What to do: Pin or upgrade to a commit newer than 5c99a95880401e2599638d567abc0e240396cb42 once maintainers publish a fix, since no fixed release version is identified in the advisory. In the meantime, isolate the robot's ROS/DDS network (dedicated ROS_DOMAIN_ID, firewalled or air-gapped WiFi) so untrusted peers cannot reach traj_server and EGOReplanFSM topics, and add a supervisor or watchdog that restarts traj_server and triggers a safe hover/land on command timeout. Review flight logs for repeated emergency-recovery cycles or runaway resource use by traj_server/poscmd_2_odom, which would indicate the faulty interaction being exercised.
| ZJU-FAST-Lab EGO-Planner-v2 | All versions up to and including commit 5c99a95880401e2599638d567abc0e240396cb42 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via thenteraction between traj_server, poscmd_2_odom, and the EGOReplanFSM emergency recovery logic
- Weakness
- CWE-400
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.