Uncontrolled Memory Allocation in Fast DDS - CVE-2026-45097
Published: July 22, 2026
Fast DDS
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to memory allocation with excessive size value in DynamicType CDR deserialization when processing a crafted CDR wire buffer containing an unbounded sequence_length value. A remote attacker can send a specially crafted serialized sample to cause a denial of service.
Both XCDRv1 and XCDRv2 deserialization paths are affected, and the issue impacts subscribers using DynamicTypes.