CryptoLib
Nasa · 27 CVEs
NASA CryptoLib 1.5.0 - TC receive path accepts Security Associations from the wrong GVCID
Sep 18, 2026
CryptoLib Has Heap Buffer Overflow Vulnerability in KMC Base64 Decode Handling (KMC JSON base64ciphertext/base64clearte…
Jan 10, 2026
CryptoLib Vulnerable to Heap Buffer Overflow in MariaDB SA Hexstring Conversion
Jan 10, 2026
CryptoLib Unbounded Memory Allocation in KMC HTTP Response Handler Allows Resource Exhaustion
Jan 10, 2026
CryptoLib Memory Leak on HTTP Error Response in KMC Client
Jan 10, 2026
CryptoLib Memory Leak in KMC Encrypt Function Leads to Resource Exhaustion
Jan 10, 2026
CryptoLib Has Out-of-Bounds Read in KMC AEAD Encrypt Metadata Parsing via Flawed strtok Pattern
Jan 10, 2026
CryptoLib Has Out-of-Bounds Read in KMC Encrypt Metadata Parsing via Flawed strtok Pattern
Jan 10, 2026
CryptoLib has an out-of-bounds read and crash vulnerability when decoding an empty Base64url string
Jan 10, 2026
CryptoLib Has Out-of-bounds Read in Crypto_AOS_ProcessSecurity
Jan 10, 2026
CryptoLib Has Out-of-Bounds Write in Crypto_Config_Add_Gvcid_Managed_Parameters
Jan 10, 2026
CryptoLib vulnerable to Stack Buffer Overflow in Crypto_Key_Update due to missing TLV length check
Oct 30, 2025
CryptoLib command Injection vulnerability in initialize_kerberos_keytab_file_login()
Sep 23, 2025
Heap Buffer Overflow in NASA CryptoLib 1.4.0 `Crypto_TC_Check_IV_Setup`
Aug 11, 2025
In NASA CryptoLib before 1.3.2, the key state is not checked before use, potentially leading to spacecraft hijacking.
Apr 27, 2025
NASA CryptoLib before 1.3.2 uses Extended Procedures that are a Work in Progress (not intended for use during flight),…
Apr 27, 2025
NASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use, possibly leading to a…
Apr 27, 2025
NASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft…
Apr 27, 2025
Heap Buffer Overflow via Incomplete Length Check in `Crypto_TC_ApplySecurity`
Apr 1, 2025
CryptoLib Has Heap Overflow in Crypto_TM_ProcessSecurity due to Unchecked Secondary Header Length
Mar 25, 2025
CryptoLib's Crypto_TC_Prep_AAD Has Buffer Overflow Due to Integer Underflow
Mar 17, 2025
CryptoLib Has Heap Buffer Overflow Due to Unsigned Integer Underflow in Crypto_TC_ProcessSecurity
Mar 17, 2025
CryptoLib Has Heap Buffer Overflow in Crypto_AOS_ProcessSecurity Function
Mar 17, 2025
CryptoLib's crypto_handle_incrementing_nontransmitted_counter Function has Memory Leak
Mar 17, 2025
CryptoLib's Crypto_TC_ApplySecurity() Has a Heap Buffer Overflow Vulnerability
Mar 17, 2025
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-79954 | NASA CryptoLib 1.5.0 - TC receive path accepts Security Associations from the wrong GVCID | HIGH | 0.56% | Sep 18, 2026 |
| CVE-2026-22697 | CryptoLib Has Heap Buffer Overflow Vulnerability in KMC Base64 Decode Handling (KMC JSON base64ciphertext/base64cleartext) | HIGH | 0.54% | Jan 10, 2026 |
| CVE-2026-22027 | CryptoLib Vulnerable to Heap Buffer Overflow in MariaDB SA Hexstring Conversion | MEDIUM | 0.24% | Jan 10, 2026 |
| CVE-2026-22026 | CryptoLib Unbounded Memory Allocation in KMC HTTP Response Handler Allows Resource Exhaustion | HIGH | 0.63% | Jan 10, 2026 |
| CVE-2026-22025 | CryptoLib Memory Leak on HTTP Error Response in KMC Client | MEDIUM | 0.54% | Jan 10, 2026 |
| CVE-2026-22024 | CryptoLib Memory Leak in KMC Encrypt Function Leads to Resource Exhaustion | MEDIUM | 0.48% | Jan 10, 2026 |
| CVE-2026-22023 | CryptoLib Has Out-of-Bounds Read in KMC AEAD Encrypt Metadata Parsing via Flawed strtok Pattern | HIGH | 0.57% | Jan 10, 2026 |
| CVE-2026-21900 | CryptoLib Has Out-of-Bounds Read in KMC Encrypt Metadata Parsing via Flawed strtok Pattern | HIGH | 0.60% | Jan 10, 2026 |
| CVE-2026-21899 | CryptoLib has an out-of-bounds read and crash vulnerability when decoding an empty Base64url string | MEDIUM | 0.34% | Jan 10, 2026 |
| CVE-2026-21898 | CryptoLib Has Out-of-bounds Read in Crypto_AOS_ProcessSecurity | HIGH | 0.45% | Jan 10, 2026 |
| CVE-2026-21897 | CryptoLib Has Out-of-Bounds Write in Crypto_Config_Add_Gvcid_Managed_Parameters | HIGH | 0.28% | Jan 10, 2026 |
| CVE-2025-64096 | CryptoLib vulnerable to Stack Buffer Overflow in Crypto_Key_Update due to missing TLV length check | HIGH | 0.52% | Oct 30, 2025 |
| CVE-2025-59534 | CryptoLib command Injection vulnerability in initialize_kerberos_keytab_file_login() | HIGH | 0.91% | Sep 23, 2025 |
| CVE-2025-54878 | Heap Buffer Overflow in NASA CryptoLib 1.4.0 `Crypto_TC_Check_IV_Setup` | HIGH | 0.39% | Aug 11, 2025 |
| CVE-2025-46675 | In NASA CryptoLib before 1.3.2, the key state is not checked before use, potentially leading to spacecraft hijacking. | MEDIUM | 0.35% | Apr 27, 2025 |
| CVE-2025-46674 | NASA CryptoLib before 1.3.2 uses Extended Procedures that are a Work in Progress (not intended for use during flight), potentially leading to a keystream oracl… | CRITICAL | 0.60% | Apr 27, 2025 |
| CVE-2025-46673 | NASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use, possibly leading to a bypass of the Space Data Link Security p… | CRITICAL | 0.50% | Apr 27, 2025 |
| CVE-2025-46672 | NASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft hijacking. | HIGH | 0.53% | Apr 27, 2025 |
| CVE-2025-30356 | Heap Buffer Overflow via Incomplete Length Check in `Crypto_TC_ApplySecurity` | CRITICAL | 0.66% | Apr 1, 2025 |
| CVE-2025-30216 | CryptoLib Has Heap Overflow in Crypto_TM_ProcessSecurity due to Unchecked Secondary Header Length | CRITICAL | 2.65% | Mar 25, 2025 |
| CVE-2025-29913 | CryptoLib's Crypto_TC_Prep_AAD Has Buffer Overflow Due to Integer Underflow | HIGH | 0.72% | Mar 17, 2025 |
| CVE-2025-29912 | CryptoLib Has Heap Buffer Overflow Due to Unsigned Integer Underflow in Crypto_TC_ProcessSecurity | HIGH | 1.12% | Mar 17, 2025 |
| CVE-2025-29911 | CryptoLib Has Heap Buffer Overflow in Crypto_AOS_ProcessSecurity Function | HIGH | 0.74% | Mar 17, 2025 |
| CVE-2025-29910 | CryptoLib's crypto_handle_incrementing_nontransmitted_counter Function has Memory Leak | MEDIUM | 0.49% | Mar 17, 2025 |
| CVE-2025-29909 | CryptoLib's Crypto_TC_ApplySecurity() Has a Heap Buffer Overflow Vulnerability | HIGH | 1.08% | Mar 17, 2025 |
Showing 1 to 25 of 27 CVEs