PT-2026-76756 · Tier Iv · Nebula

·

CVE-2026-74238

·

Published

2026-08-17

·

Updated

2026-08-20

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions TIER IV Nebula versions prior to 1.2.1
Description An out-of-bounds read exists in the Vlp32Decoder::unpack() function. This allows unauthenticated remote attackers to cause the decoder to read past the end of a received UDP buffer into adjacent heap memory by sending a short UDP datagram. By sending a malformed datagram to the Velodyne UDP sensor port, which lacks the sender-address restrictions found in other drivers, attackers can cause fabricated points derived from heap memory contents to be silently published into downstream PointCloud2 messages consumed by Autoware nodes.
Recommendations Update TIER IV Nebula to a version newer than 1.2.0. As a temporary workaround, restrict access to the Velodyne UDP sensor port to minimize the risk of exploitation.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74238

Affected Products

Nebula