CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-53985

highCVSS 7.5covered by 1 sourcefirst seen 2026-08-06
Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vulnerability in the Socket.IO server's service_control event handler that allows any unauthenticated network peer to forcibly terminate the ground-station process by sending a single restart_service command. Attackers can connect to the Socket.IO server on port 7000 without credentials due to disabled authentication enforcement and a wildcard CORS policy, then emit the service_control event to terminate all active satellite-tracking sessions, SDR recording pipelines, demodulators, decoders, and rotator controllers, with repeated triggering possible in Docker deployments to create a persistent denial-of-service condition.

⚡ Watch CVE-2026-53985

Get an email if CVE-2026-53985 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-53985

CVE.org record

Embed the live status

CVE-2026-53985 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-53985 status](https://www.csirts.com/badge/CVE-2026-53985)](https://www.csirts.com/cve/CVE-2026-53985)