# NASA's cFS Health Monitor Can Be Crashed Remotely — And the First Patch Didn't Fully Fix It


## The Threat


The NASA Core Flight System — the open-source software stack that powers flight software across NASA missions and an expanding number of aerospace and commercial operators — has a remotely exploitable null pointer dereference in its Health and Safety (HS) application. A successful exploit crashes the HS process and triggers a processor reset: a denial-of-service that, depending on the mission phase and system redundancy, could mean anything from a brief outage to a loss-of-command scenario.


What makes this particularly uncomfortable is the backstory. CVE-2026-18064 exists because CVE-2026-15352 — a prior null pointer dereference in the same component — was patched incompletely. The fix addressed one code path but left a separate reachable dereference intact through version 7.0.1. That's not a novel bug category; it's an incomplete remediation that had to be reported by an outside researcher before NASA caught it.


The vector is network-adjacent and requires no authentication. An attacker who can send crafted commands to the HS application under specific triggering conditions can pull this off without privilege, without user interaction, and without needing a foothold anywhere else on the system. For ground-support software or any cFS deployment with a network-accessible command interface, that's a meaningful attack surface.


## Severity and Impact


| Field | Detail |

|---|---|

| CVE | CVE-2026-18064 |

| CWE | CWE-476 (NULL Pointer Dereference) |

| CVSS v3.1 Score | 7.5 HIGH |

| CVSS v3.1 Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |

| CVSS v4.0 Score | 8.2 HIGH |

| CVSS v4.0 Vector | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |

| Attack Complexity | Low (v3.1) / Low with attack requirements (v4.0) |

| Authentication Required | None |

| Impact | HS application crash + processor reset (availability only) |

| Reported By | Michael Holmquist, Hasp Labs |


## Affected Products


  • NASA Core Flight System (cFS) Health & Safety (HS) Application — all versions through and including v7.0.1

  • Deployed worldwide across Transportation Systems critical infrastructure sector and NASA mission ground and flight software environments.


    ## Mitigations


    No official stable release patch exists yet. NASA has confirmed a fix is under development. In the interim:


  • Immediate workaround: Pull the latest code from the dev branch of the [NASA HS GitHub repository](https://github.com/nasa/HS). The fix is present starting at commit 828855f971db4b6714367ed0a970f52dbeab2965.
  • Network isolation: Remove HS application command interfaces from any internet-accessible network. Treat all cFS command buses as internal-only.
  • Firewall segmentation: Place cFS deployments behind dedicated firewalls, isolated from general IT networks. Do not bridge business network segments to flight software networks.
  • VPN for remote access: If remote command access is operationally necessary, route it through a current, patched VPN with strong authentication — and audit who has access.
  • Monitor for anomalies: Watch for unexpected HS application restarts or processor resets; these could be exploitation indicators or precursors to a targeted attack.
  • Report incidents: Organizations observing suspected exploitation should report to CISA for correlation across the broader ICS threat landscape.

  • ## References


  • [CISA Advisory — NASA cFS Health & Safety (HS) Application](https://www.cisa.gov/news-events/ics-advisories/)
  • [NASA HS GitHub Repository](https://github.com/nasa/HS)
  • [CVE-2026-18064 Details](https://www.cve.org/)
  • [CISA ICS Security Best Practices](https://www.cisa.gov/ics)

  • ---


    ## HackWire Analysis


    The headline vulnerability here isn't really the null pointer dereference — those are almost mundane at this point. The story is the failed patch. CVE-2026-15352 was already a known null pointer dereference in the same HS module. Someone fixed one triggerable path, called it done, and shipped 7.0.1. An outside researcher at Hasp Labs then found the second path and had to loop in CISA to get it addressed. That sequence — incomplete remediation followed by external discovery — is a pattern that should concern anyone running cFS in production.


    NASA's Core Flight System has grown well beyond its origins as internal mission software. It's now openly licensed and increasingly adopted by commercial space operators, smallsat developers, and aerospace contractors who benefit from a battle-hardened, open-source flight software framework without the cost of building from scratch. That adoption amplifies the blast radius of any vulnerability. A bug in cFS is no longer just a NASA problem.


    The CVSS 4.0 score introducing "attack requirements" (AT:P) is worth reading carefully. It acknowledges that triggering the dereference requires specific conditions — an attacker needs to know the right command structure and timing. That's not a high bar for a well-resourced adversary with access to the open-source codebase and documentation. Anyone who has studied the HS application's command handler can map the triggerable paths. The code is public.


    For defenders: if you're running cFS in any capacity — ground support, lab integration, or production — cherry-pick that commit now. Don't wait for the official release. The dev branch fix is concrete and auditable. And review your network architecture: if the cFS command bus has any path to a network interface that isn't strictly controlled, fix that before you fix the software.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)