CVE-2026-22591
Awaiting Analysis Awaiting Analysis - Queue

Denial of Service in eprosima Fast DDS via SQL Filter Injection

Vulnerability report for CVE-2026-22591, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-14

Assigner: GitHub, Inc.

Description

eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.6.12, 2.14.6, 3.2.4, and 3.4.3, Fast DDS’s implementation of SQL‑based content filtering (DDSSQLFilter) allows any participant in a DDS domain to remotely crash other Fast DDS participants by sending a single crafted SEDP `DATA` submessage whose `PID_CONTENT_FILTER_PROPERTY.filterExpression` contains a deeply nested filter expression. Versions 2.6.12, 2.14.6, 3.2.4, and 3.4.3 fix the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-14
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
eprosima fast_dds to 3.4.1 (exc)
eprosima fast_dds 2.6.12
eprosima fast_dds 2.14.6
eprosima fast_dds 3.2.4
eprosima fast_dds 3.4.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.
CWE-674 The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stack exhaustion vulnerability in eprosima Fast DDS affecting versions before 2.6.12, 2.14.6, 3.2.4, and 3.4.3. It involves a recursive parser in the DDSSQLFilter component that handles SQL-based content filtering. An attacker can remotely crash Fast DDS participants by sending a crafted SEDP DATA submessage with a deeply nested filter expression in the PID_CONTENT_FILTER_PROPERTY.filterExpression field, causing a segmentation fault.

Detection Guidance

Monitor Fast DDS processes for crashes or segmentation faults, particularly in versions prior to 2.6.12, 2.14.6, 3.2.4, or 3.4.3. Check network traffic for SEDP DATA submessages with unusually large or nested filterExpression fields using packet capture tools like tcpdump or Wireshark.

Impact Analysis

This vulnerability allows any participant in a DDS domain to remotely crash other Fast DDS participants by sending a single malicious message. The attack does not require special privileges or matching user data topics, only network access to the victim's RTPS ports. Even with DDS Security enabled, authenticated malicious participants can still execute the attack.

Compliance Impact

This vulnerability could indirectly impact compliance with standards like GDPR or HIPAA by disrupting the availability of Fast DDS services. A denial-of-service attack crashing systems may lead to service unavailability, which could violate availability requirements in GDPR (Article 32) or HIPAA (Security Rule). However, the CVE data does not explicitly link this issue to compliance frameworks.

Mitigation Strategies

Upgrade Fast DDS to patched versions (2.6.12, 2.14.6, 3.2.4, or 3.4.3 or later) immediately. Restrict network access to RTPS ports to trusted participants only. Monitor for suspicious SEDP messages and block traffic containing deeply nested filter expressions at the network perimeter.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-22591. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart