Skip to main content
Vulnerability Database/CVE-2026-22591

CVE-2026-22591: Fast DDS SQL Filter DOS Vulnerability

CVE-2026-22591 is a denial of service vulnerability in eprosima Fast DDS that allows remote attackers to crash participants via crafted SQL filter expressions. This post covers technical details, affected versions, and mitigation.

Published:

CVE-2026-22591 Overview

CVE-2026-22591 affects eProsima Fast DDS, a C++ implementation of the Object Management Group (OMG) Data Distribution Service (DDS) standard. The vulnerability resides in the SQL-based content filtering component (DDSSQLFilter). Any participant in a DDS domain can remotely crash other Fast DDS participants by transmitting a single crafted Simple Endpoint Discovery Protocol (SEDP) DATA submessage. The malicious submessage carries a PID_CONTENT_FILTER_PROPERTY.filterExpression value containing a deeply nested filter expression that exhausts resources during parsing. The flaw is tracked as CWE-400 Uncontrolled Resource Consumption.

Critical Impact

A single crafted SEDP submessage from any domain participant crashes remote Fast DDS participants, disrupting availability of DDS-based distributed systems including robotics, autonomous vehicles, and industrial control platforms.

Affected Products

  • eProsima Fast DDS versions prior to 2.6.12 (2.6.x branch)
  • eProsima Fast DDS versions prior to 2.14.6 and 3.2.4 (2.14.x and 3.2.x branches)
  • eProsima Fast DDS versions prior to 3.4.3 (3.4.x branch)

Discovery Timeline

  • 2026-09-09 - CVE-2026-22591 published to the National Vulnerability Database
  • 2026-09-09 - Last updated in NVD database

Technical Details for CVE-2026-22591

Vulnerability Analysis

Fast DDS implements content filtering through the DDSSQLFilter component, which parses SQL-like expressions delivered via discovery messages. Participants advertise filter expressions using the PID_CONTENT_FILTER_PROPERTY parameter within SEDP DATA submessages. The parser processes nested logical operators recursively without enforcing a bound on nesting depth. An attacker constructs an expression with excessive parenthetical nesting, forcing the receiving participant to consume stack or heap resources until the process terminates. Because DDS discovery traffic propagates automatically to all participants in the domain, a single malicious message reaches every peer configured with content filtering.

Root Cause

The root cause is uncontrolled recursion during parsing of the filterExpression field. The DDSSQLFilter implementation lacks input validation on expression depth and complexity. This classification aligns with [CWE-400] Uncontrolled Resource Consumption.

Attack Vector

Exploitation requires network access to the DDS domain but no authentication or user interaction. The attacker joins the domain as an ordinary participant and publishes a crafted SEDP discovery message. All participants receiving the discovery submessage attempt to parse the nested filter expression and crash. The impact is limited to availability; confidentiality and integrity are not affected.

No verified public exploit code is available. See the GitHub Security Advisory GHSA-7577-rf2r-j88m for advisory details.

Detection Methods for CVE-2026-22591

Indicators of Compromise

  • Unexpected termination of Fast DDS participant processes shortly after new participants join the domain.
  • SEDP DATA submessages containing PID_CONTENT_FILTER_PROPERTY fields with abnormally long or deeply nested filterExpression values.
  • Repeated participant restarts or discovery churn correlated with a single peer publishing filter expressions.

Detection Strategies

  • Inspect RTPS traffic at the network layer for PID_CONTENT_FILTER_PROPERTY parameters and flag filterExpression values exceeding reasonable nesting depth or length thresholds.
  • Monitor Fast DDS log output for parser errors, stack overflow signatures, or abnormal termination of participant processes.
  • Correlate crash events across multiple hosts in a DDS domain to identify domain-wide denial of service patterns.

Monitoring Recommendations

  • Enable process crash telemetry on hosts running Fast DDS participants and forward events to a centralized SIEM.
  • Track discovery message rates and participant lifecycle events to baseline normal DDS behavior.
  • Alert on repeated participant restarts and correlate with the source of recent SEDP submessages.

How to Mitigate CVE-2026-22591

Immediate Actions Required

  • Upgrade Fast DDS to version 2.6.12, 2.14.6, 3.2.4, or 3.4.3 as appropriate for your deployed branch.
  • Inventory all applications, robots, and vehicles that embed Fast DDS and confirm patched versions are deployed.
  • Restrict DDS domain membership to trusted participants using network segmentation and DDS Security authentication.

Patch Information

The maintainers fixed the issue in Fast DDS versions 2.6.12, 2.14.6, 3.2.4, and 3.4.3. Refer to the GitHub Security Advisory GHSA-7577-rf2r-j88m for release details and patch commits.

Workarounds

  • Disable content filtering in DDS applications where the feature is not required until upgrades are completed.
  • Deploy DDS Security (authentication, access control, and encryption) to prevent untrusted participants from joining the domain.
  • Place DDS traffic on isolated network segments with strict ingress controls to limit exposure to untrusted hosts.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.