LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-32708

CVE-2026-32708 - Vulnerability Analysis

HighCVSS: 7.8

Last Updated: March 17, 2026

PX4 autopilot - Denial of Service

Published: March 16, 2026Updated: March 17, 2026PoC Available

Overview

PX4 autopilot < 1.17.0-rc2 contains a stack overflow caused by unbounded stack allocation from incoming Zenoh uORB subscriber payload length, letting remote Zenoh publishers crash the Zenoh bridge task, exploit requires sending oversized fragmented messages.

Severity & Score

Severity: High
CVSS Score: 7.8
EPSS Score: 1.6%(Probability of exploitation in next 30 days)

Impact

Remote attackers can cause a stack overflow leading to a crash of the Zenoh bridge task, resulting in denial of service.

Mitigation

Update to version 1.17.0-rc2 or later.

Social Media Activity(1 post)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 16, 2026

🟠 CVE-2026-32708 - High (7.8) PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, the Zenoh uORB subscriber allocates a stack VLA directly from the incoming payload length without bounds. A remote Zenoh publisher can send an oversized fragmented message... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-32708/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-32708
Severity
High
CVSS Score
7.8
Type
buffer_overflow
Status
modified
EPSS
1.6%
Social Posts
1

CWE

  • CWE-121

CVSS Metrics

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Score

1.6%Probability of exploitation in the next 30 days