Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vulnerability was identified in the cryptographic verification pipeline of Vanetza. When processing incoming V2X messages, the ASN.1 decoder accepts the structure as syntactically valid. However, this reveals a logic-based protocol failure where semantic constraints on specific fields are only strictly enforced during OER re-encoding. Specifically, if a crafted packet contains a certificate where the Psid (Provider Service Identifier) sub-type violates subtype constraints (e.g., out-of-range or invalid CHOICE variant), it is accepted during initial parsing, where subtype constraints are not enforced. Later, when StraightVerifyService attempts to calculate a message hash for cryptographic verification, it must re-encode the signing certificate. The underlying ASN.1 wrapper (asn1cwrapper.cpp) detects the semantic violation during encoding and raises a std::runtimeerror. This exception is not caught within the encoding path and propagates to std::terminate, resulting in immediate process termination. This vulnerability is fixed with commit e1a2e2709210d309458c3d77f98d50dec26c0df0.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44905.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"fixed": "e1a2e2709210d309458c3d77f98d50dec26c0df0"
}
],
"source": "AFFECTED_FIELD"
}
],
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-248"
]
}[
{
"digest": {
"line_hashes": [
"169467805809650100907254097227535752772",
"14041500191709272601141769165788347043",
"200498007955823437206347493676005167514",
"303546908535609357706725288682390875012",
"222431100608473746886292800090134048161",
"58442767986675785543773197795781573982",
"318994315303756853649180777306688923296"
],
"threshold": 0.9
},
"signature_type": "Line",
"deprecated": false,
"id": "CVE-2026-44905-61e6ee49",
"target": {
"file": "vanetza/security/straight_verify_service.cpp"
},
"source": "https://github.com/riebl/vanetza/commit/e1a2e2709210d309458c3d77f98d50dec26c0df0",
"signature_version": "v1"
},
{
"digest": {
"function_hash": "216969328075873767355756843707141070872",
"length": 4405.0
},
"signature_type": "Function",
"deprecated": false,
"id": "CVE-2026-44905-fe516727",
"target": {
"file": "vanetza/security/straight_verify_service.cpp",
"function": "StraightVerifyService::verify"
},
"source": "https://github.com/riebl/vanetza/commit/e1a2e2709210d309458c3d77f98d50dec26c0df0",
"signature_version": "v1"
}
]
"2026-07-27T09:24:32Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44905.json"