VendorsNASAcryptolibany version
Vulnerabilities

NASA Cryptolib any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

24CVEs
CVE-2025-46674
NASA CryptoLib before 1.3.2 uses Extended Procedures that are a Work in Progress (not intended for use during flight), potentially leading to a keystream oracle.
Published 2025-04-27 · Analyzed
9.9EPSS 0.006
CVE-2025-46673
NASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use, possibly leading to a bypass of the Space Data Link Security protocol (SDLS).
Published 2025-04-27 · Analyzed
9.9EPSS 0.005
CVE-2025-29912
CryptoLib Has Heap Buffer Overflow Due to Unsigned Integer Underflow in Crypto_TC_ProcessSecurity
Published 2025-03-17 · Analyzed
9.8EPSS 0.011
CVE-2025-29909
CryptoLib's Crypto_TC_ApplySecurity() Has a Heap Buffer Overflow Vulnerability
Published 2025-03-17 · Analyzed
9.8EPSS 0.011
CVE-2025-29911
CryptoLib Has Heap Buffer Overflow in Crypto_AOS_ProcessSecurity Function
Published 2025-03-17 · Analyzed
9.8EPSS 0.007
CVE-2025-29913
CryptoLib's Crypto_TC_Prep_AAD Has Buffer Overflow Due to Integer Underflow
Published 2025-03-17 · Analyzed
9.8EPSS 0.007
CVE-2025-30356
Heap Buffer Overflow via Incomplete Length Check in `Crypto_TC_ApplySecurity`
Published 2025-04-01 · Analyzed
9.8EPSS 0.006
CVE-2025-30216
CryptoLib Has Heap Overflow in Crypto_TM_ProcessSecurity due to Unchecked Secondary Header Length
Published 2025-03-25 · Analyzed
9.4EPSS 0.026
CVE-2025-46672
NASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft hijacking.
Published 2025-04-27 · Analyzed
8.8EPSS 0.005
CVE-2025-64096
CryptoLib vulnerable to Stack Buffer Overflow in Crypto_Key_Update due to missing TLV length check
Published 2025-10-30 · Modified
8.8EPSS 0.005
CVE-2025-54878
Heap Buffer Overflow in NASA CryptoLib 1.4.0 `Crypto_TC_Check_IV_Setup`
Published 2025-08-11 · Analyzed
8.6EPSS 0.004
CVE-2026-22026
CryptoLib Unbounded Memory Allocation in KMC HTTP Response Handler Allows Resource Exhaustion
Published 2026-01-10 · Analyzed
8.2EPSS 0.006
CVE-2026-21900
CryptoLib Has Out-of-Bounds Read in KMC Encrypt Metadata Parsing via Flawed strtok Pattern
Published 2026-01-10 · Analyzed
8.2EPSS 0.006
CVE-2026-22023
CryptoLib Has Out-of-Bounds Read in KMC AEAD Encrypt Metadata Parsing via Flawed strtok Pattern
Published 2026-01-10 · Analyzed
8.2EPSS 0.006
CVE-2026-21898
CryptoLib Has Out-of-bounds Read in Crypto_AOS_ProcessSecurity
Published 2026-01-10 · Analyzed
8.2EPSS 0.005
CVE-2025-59534
CryptoLib command Injection vulnerability in initialize_kerberos_keytab_file_login()
Published 2025-09-23 · Analyzed
7.8EPSS 0.009
CVE-2026-22697
CryptoLib Has Heap Buffer Overflow Vulnerability in KMC Base64 Decode Handling (KMC JSON base64ciphertext/base64cleartext)
Published 2026-01-10 · Analyzed
7.5EPSS 0.005
CVE-2025-29910
CryptoLib's crypto_handle_incrementing_nontransmitted_counter Function has Memory Leak
Published 2025-03-17 · Analyzed
7.5EPSS 0.005
CVE-2026-21897
CryptoLib Has Out-of-Bounds Write in Crypto_Config_Add_Gvcid_Managed_Parameters
Published 2026-01-10 · Analyzed
7.3EPSS 0.003
CVE-2026-22025
CryptoLib Memory Leak on HTTP Error Response in KMC Client
Published 2026-01-10 · Analyzed
6.3EPSS 0.005
CVE-2026-22024
CryptoLib Memory Leak in KMC Encrypt Function Leads to Resource Exhaustion
Published 2026-01-10 · Analyzed
6.3EPSS 0.005
CVE-2026-22027
CryptoLib Vulnerable to Heap Buffer Overflow in MariaDB SA Hexstring Conversion
Published 2026-01-10 · Analyzed
6.0EPSS 0.002
CVE-2026-21899
CryptoLib has an out-of-bounds read and crash vulnerability when decoding an empty Base64url string
Published 2026-01-10 · Analyzed
4.9EPSS 0.004
CVE-2025-46675
In NASA CryptoLib before 1.3.2, the key state is not checked before use, potentially leading to spacecraft hijacking.
Published 2025-04-27 · Analyzed
4.2EPSS 0.004