CVE-2026-71643
nicheUnauthenticated Denial of Service in ZJU-FAST-Lab EGO-Planner-v2 EGOReplanFSM
ZJU-FAST-Lab EGO-Planner-v2, an open-source quadrotor trajectory planning framework, contains an uncontrolled resource consumption flaw (CWE-400) in its EGOReplanFSM finite-state-machine component. An unauthenticated remote attacker on a reachable network can send crafted input that exhausts resources (e.g., CPU/memory or repeated replanning loops), crashing or hanging the planner and causing high availability impact (CVSS 3.1: 7.5, AV:N/AC:L/PR:N/UI:N). The practical consequence for an affected drone is loss of autonomous local replanning, which can force the vehicle to hover, abort, or land. All forks and checkouts up to and including commit 5c99a95880401e2599638d567abc0e240396cb42 are affected. No public proof-of-concept or known in-the-wild exploitation has been reported, and the flaw is not in the CISA KEV catalog.
What to do: Update your EGO-Planner-v2 checkout to the latest upstream commit on the ZJU-FAST-Lab repository, since all versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 are affected. Because ROS 1 topics and services have no authentication, isolate the drone's ROS network (dedicated link, VPN, or firewall rules) so untrusted parties cannot reach the EGOReplanFSM node, and supervise the planner process with an automatic restart plus a safe hover/land fallback if it crashes. Review logs for repeated replanning loops or abnormal CPU/memory spikes in the planner node as an indicator of triggered resource exhaustion.
| ZJU-FAST-Lab EGO-Planner-v2 | All versions up to and including commit 5c99a95880401e2599638d567abc0e240396cb42 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via the EGOReplanFSM component
- Weakness
- CWE-400
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.