{"id":"CVE-2026-43988","summary":"Vanetza: Remote Denial of Service via Uncaught Exception in ASN.1/OER Parsing","details":"Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vulnerability was identified in the ASN.1/OER parsing pipeline of Vanetza. When processing malformed network packets containing corrupted ASN.1/OER structures (e.g., invalid length fields or malformed certificate encoding), the ASN.1 wrapper (asn1c_wrapper.cpp) raises a std::runtime_error. This exception is not caught at the parsing boundary and propagates to std::terminate, resulting in process termination. This vulnerability is fixed with commit 62dfe58a8342512b6e1947d75821402ada524f1a.","aliases":["GHSA-j6cj-rp87-mfrx"],"modified":"2026-08-12T16:24:26.132022Z","published":"2026-05-26T21:17:23.568Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43988.json","unresolved_ranges":[{"extracted_events":[{"fixed":"62dfe58a8342512b6e1947d75821402ada524f1a"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"GitHub_M","cwe_ids":["CWE-248"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43988.json"},{"type":"ADVISORY","url":"https://github.com/riebl/vanetza/security/advisories/GHSA-j6cj-rp87-mfrx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-43988"},{"type":"FIX","url":"https://github.com/riebl/vanetza/commit/62dfe58a8342512b6e1947d75821402ada524f1a"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/riebl/vanetza","events":[{"introduced":"0"},{"fixed":"62dfe58a8342512b6e1947d75821402ada524f1a"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"26.02"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v26.02","v25.06","v24.10"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-43988.json","vanir_signatures_modified":"2026-08-12T16:24:26Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["120507183913642992934266718702661940086","183338805295403297330024893950020628936","77955727460362536017711021380369810000","94297039552648898801132085787498314694","21380716296705308477510179655215789524","225063994239765396802749549561499763404","112266516912872078834209402227453311736","309245407206844181951266235836169414728","299650765213192288583726772910521231973"],"threshold":0.9},"id":"CVE-2026-43988-bd566552","signature_type":"Line","signature_version":"v1","source":"https://github.com/riebl/vanetza/commit/62dfe58a8342512b6e1947d75821402ada524f1a","target":{"file":"vanetza/security/v3/certificate.cpp"}},{"digest":{"function_hash":"94071187413114370352983363581339720182","length":1607},"id":"CVE-2026-43988-f33f0e00","signature_type":"Function","signature_version":"v1","source":"https://github.com/riebl/vanetza/commit/62dfe58a8342512b6e1947d75821402ada524f1a","target":{"file":"vanetza/security/v3/certificate.cpp","function":"canonicalize"},"deprecated":false}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}