VendorsOpennavnav2all versions
Vulnerabilities

Opennav Open Navigaion Nav2 (Navigation2)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2026-26011
Critical Heap Out-of-bounds Access in `pf_cluster_stats()` via Malicious /initialpose Covariance -- Potential Remote Code Execution
Published 2026-02-12 · Analyzed
9.8EPSS 0.007
CVE-2024-25198
Inappropriate pointer order of laser_scan_filter_.reset() and tf_listener_.reset() (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions leads to a use-after-free.
Published 2024-02-20 · Analyzed
9.1EPSS 0.007
CVE-2024-25199
Inappropriate pointer order of map_sub_ and map_free(map_) (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions leads to a use-after-free.
Published 2024-02-20 · Analyzed
8.1EPSS 0.006
CVE-2024-25197
Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a NULL pointer dereference via the isCurrent() function at /src/layered_costmap.cpp.
Published 2024-02-20 · Analyzed
6.5EPSS 0.007
CVE-2024-25196
Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_controller process. This vulnerability is triggerd via sending a crafted .yaml file.
Published 2024-02-20 · Analyzed
3.3EPSS 0.003