CVE-2026-71645
nicheUnauthenticated Denial of Service in RACER Exploration State Machine
RACER, an open-source robotic exploration framework from Robotics-STAR-Lab (SYSU STAR Group), improperly handles exceptional conditions (CWE-703) in its exploration state machine at commit abcdef1234567890. A remote, unauthenticated attacker with network access to the affected component can trigger a failure in the state machine that causes the exploration process to hang or crash, resulting in denial of service of the robot's autonomous exploration capability. Confidentiality and integrity are not affected; only availability, which is rated high impact (CVSS 3.1: 7.5). The flaw affects anyone running the identified commit of RACER, which is primarily academic and research robotics deployments. There is no known public proof of concept and no evidence of exploitation in the wild.
What to do: Upgrade to or pin a version of RACER later than commit abcdef1234567890 once a fix is available, and audit any deployments still running the affected commit. Restrict network access to the exploration state machine's ROS topics and services using network segmentation or DDS/ROS 2 transport security so only trusted hosts can reach it. Monitor the exploration node for unexpected hangs or crashes that could indicate a malformed-input DoS attempt.
| Robotics-STAR-Lab (SYSU STAR Group) RACER | commit abcdef1234567890 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause a denial of service via the exploration state machine
- Weakness
- CWE-703
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.