Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Fast-DDS — Vulnerabilities & Security Advisories 23

All 23 CVE vulnerabilities found in Fast-DDS, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities for Fast-DDS, a vendor-specific middleware product, categorized by Common Weakness Enumeration types. It collects known flaws, including memory corruption, input validation errors, and denial-of-service conditions, covering advisories from 2023 through 2024. Here, you can track the vendor's security advisories, analyze specific weakness classes, and review the complete vulnerability history for the product.

Vendor: eProsima

CVE ID Title CVSS Severity Published
CVE-2026-22591 Fast DDS DDSSQLFilter Recursive Parser Stack Exhaustion (Remote DoS) CWE-400 7.5 High 2026-09-09
CVE-2026-22590 Fast-DDS Discovery Server: Out-of-Bounds Read & Heap Memory Disclosure via DATA_FRAG  sampleSize / fragmentsInSubmessage CWE-125 9.1 Critical 2026-09-09
CVE-2025-64438 Fast-DDS: Unbounded GAP range triggers OOM DoS under RELIABLE QoS CWE-835 7.5AI High AI 2026-02-03
CVE-2025-64098 FastDDS has Out-of-memory in readOctetVector via Manipulated DATA Submessage when DDS Security is enabled CWE-125 7.5AI High AI 2026-02-03
CVE-2025-62799 FastDDS's heap buffer overflow in RTPS DATA_FRAG enables unauthenticated DoS (potential RCE) CWE-122 9.8AI Critical AI 2026-02-03
CVE-2025-62603 FastDDS has Out-of-memory while parsing GenericMessage when DDS Security is enabled CWE-125 9.8AI Critical AI 2026-02-03
CVE-2025-62602 FastDDS has heap buffer overflow in readData via Manipulated DATA Submessage when DDS Security is enabled CWE-122 7.5AI High AI 2026-02-03
CVE-2025-62601 FastDDS has heap buffer overflow in readString via Manipulated DATA Submessage when DDS Security is enabled CWE-122 7.5AI High AI 2026-02-03
CVE-2025-62600 eprosima Fast DDS affected by Out-of-Memory in readBinaryPropertySeq via Manipulated DATA Submessage when DDS Security is enabled CWE-190 8.6 High 2026-02-03
CVE-2025-62599 eprosima Fast DDS affected by Out-of-Memory in readPropertySeq via Manipulated DATA Submessage when DDS Security is enabled CWE-190 8.6 High 2026-02-03
CVE-2025-24807 Fast DDS does not verify Permissions CA CWE-345 9.1 - 2025-02-11
CVE-2024-30259 FastDDS heap buffer overflow when publisher sends malformed packet CWE-120 8.2 High 2024-05-13
CVE-2024-30258 FastDDS crash when publisher send malformed packet CWE-20 8.2 High 2024-05-13
CVE-2024-28231 Manipulated DATA Submessage causes a heap-buffer-overflow error CWE-122 9.7 Critical 2024-03-20
CVE-2023-50716 Invalid DATA_FRAG Submessage causes a bad-free error CWE-416 9.7 Critical 2024-03-06
CVE-2023-50257 Disconnect Vulnerability in RTPS Packets Used by SROS2 CWE-284 9.7 Critical 2024-02-19
CVE-2023-42459 Malformed DATA submessage leads to bad-free error in Fast-DDS CWE-415 8.6 High 2023-10-16
CVE-2023-39949 Improper validation of sequence numbers leading to remotely reachable assertion failure CWE-617 7.5 High 2023-08-11
CVE-2023-39948 Uncaught fastcdr exception (Unexpected CDR type received) crashing fastdds CWE-248 7.5 High 2023-08-11
CVE-2023-39947 Another heap overflow in push_back_helper CWE-122 8.2 High 2023-08-11
CVE-2023-39946 Heap overflow in push_back_helper due to a CDR message CWE-122 8.2 High 2023-08-11
CVE-2023-39945 Malformed serialized data in a data submessage leads to unhandled exception CWE-248 8.2 High 2023-08-11
CVE-2023-39534 Malformed GAP submessage triggers assertion failure CWE-617 7.5 High 2023-08-11

All 23 known CVE vulnerabilities affecting Fast-DDS with full Chinese analysis, references, and POCs where available.