CVE-2026-48140

Source
https://cve.org/CVERecord?id=CVE-2026-48140
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-48140.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-48140
Aliases
  • GHSA-prfr-q8h3-mqxv
Published
2026-06-19T14:16:23.063Z
Modified
2026-08-07T11:51:16.839641244Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

There is an unchecked enum cast vulnerability in NI grpc-device BeginSidebandStream that may allow an attacker to trigger invalid enum states and undefined behavior, potentially resulting in a denial of service. Successful exploitation requires an attacker to supply a specially crafted message containing an out-of-range value. This affects NI grpc-device 2.17.0 and prior versions.

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "last_affected": "2025"
                }
            ],
            "vendor_product": "ni:instrumentstudio",
            "source": "CPE_RANGE",
            "cpes": [
                "cpe:2.3:a:ni:instrumentstudio:*:*:*:*:*:*:*:*"
            ]
        },
        {
            "extracted_events": [
                {
                    "introduced": "2026-q1"
                },
                {
                    "last_affected": "2026-q1"
                },
                {
                    "introduced": "2026-q2"
                },
                {
                    "last_affected": "2026-q2"
                }
            ],
            "vendor_product": "ni:instrumentstudio",
            "source": "CPE_STRING",
            "cpes": [
                "cpe:2.3:a:ni:instrumentstudio:2026:q1:*:*:*:*:*:*",
                "cpe:2.3:a:ni:instrumentstudio:2026:q2:*:*:*:*:*:*"
            ]
        }
    ]
}
References

Affected packages

Git / github.com/ni/grpc-device

Affected ranges

Type
GIT
Repo
https://github.com/ni/grpc-device
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.18.0"
        }
    ],
    "cpe": "cpe:2.3:a:ni:ni_grpc_device_server:*:*:*:*:*:*:*:*",
    "source": "CPE_RANGE"
}

Affected versions

v0.*
v0.1
v0.1.1
v1.*
v1.0.0
v1.1.0
v1.1.0-internal
v1.1.0-rc0
v1.1.0-rc1
v1.2.0
v1.4.0
v1.5.0
v1.5.1
v2.*
v2.10.0
v2.11.0
v2.12.0
v2.13.0
v2.15.0
v2.16.0
v2.17.0
v2.2
v2.2.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-48140.json"