Home

Description

Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vulnerability was identified in the cryptographic verification pipeline of Vanetza. When processing incoming V2X messages, the ASN.1 decoder accepts the structure as syntactically valid. However, this reveals a logic-based protocol failure where semantic constraints on specific fields are only strictly enforced during OER re-encoding. Specifically, if a crafted packet contains a certificate where the Psid (Provider Service Identifier) sub-type violates subtype constraints (e.g., out-of-range or invalid CHOICE variant), it is accepted during initial parsing, where subtype constraints are not enforced. Later, when StraightVerifyService attempts to calculate a message hash for cryptographic verification, it must re-encode the signing certificate. The underlying ASN.1 wrapper (asn1c_wrapper.cpp) detects the semantic violation during encoding and raises a std::runtime_error. This exception is not caught within the encoding path and propagates to std::terminate, resulting in immediate process termination. This vulnerability is fixed with commit e1a2e2709210d309458c3d77f98d50dec26c0df0.

PUBLISHED Reserved 2026-05-07 | Published 2026-05-26 | Updated 2026-05-27 | Assigner GitHub_M




HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem types

CWE-248: Uncaught Exception

Product status

< e1a2e2709210d309458c3d77f98d50dec26c0df0
affected

<= 26.02
affected

References

github.com/...anetza/security/advisories/GHSA-q9fq-3rx9-7xcv exploit

github.com/...anetza/security/advisories/GHSA-q9fq-3rx9-7xcv

github.com/...ommit/e1a2e2709210d309458c3d77f98d50dec26c0df0

cve.org (CVE-2026-44905)

nvd.nist.gov (CVE-2026-44905)

Download JSON