ZeroHour

CVE-2026-71645

niche

Unauthenticated Denial of Service in RACER Exploration State Machine

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

RACER, an open-source robotic exploration framework from Robotics-STAR-Lab (SYSU STAR Group), improperly handles exceptional conditions (CWE-703) in its exploration state machine at commit abcdef1234567890. A remote, unauthenticated attacker with network access to the affected component can trigger a failure in the state machine that causes the exploration process to hang or crash, resulting in denial of service of the robot's autonomous exploration capability. Confidentiality and integrity are not affected; only availability, which is rated high impact (CVSS 3.1: 7.5). The flaw affects anyone running the identified commit of RACER, which is primarily academic and research robotics deployments. There is no known public proof of concept and no evidence of exploitation in the wild.

What to do: Upgrade to or pin a version of RACER later than commit abcdef1234567890 once a fix is available, and audit any deployments still running the affected commit. Restrict network access to the exploration state machine's ROS topics and services using network segmentation or DDS/ROS 2 transport security so only trusted hosts can reach it. Monitor the exploration node for unexpected hangs or crashes that could indicate a malformed-input DoS attempt.

Affected
Robotics-STAR-Lab (SYSU STAR Group) RACERcommit abcdef1234567890
Estimated exposure
nicheunknown; likely on the order of tens to low hundreds of research/lab deployments — RACER is an academic open-source robotics repository distributed via GitHub with no published install or download metrics, and such frameworks are typically run in isolated lab or simulation environments rather than internet-facing…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause a denial of service via the exploration state machine

Weakness
CWE-703
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.