Out-of-Bounds Read in CryptoLib Affects NASA's Core Flight System
CVE-2026-21899
4.7MEDIUM
What is CVE-2026-21899?
CryptoLib, a library ensuring secure communications for spacecraft utilizing the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP), was found to allow an out-of-bounds read due to improper input handling in its base64urlDecode function. Specifically, before version 1.4.3, the code did not validate the input length, leading to potential crashes when processing empty or NULL inputs. This vulnerability could affect essential operations in space missions, necessitating immediate action through the upgrade to version 1.4.3, where this issue has been rectified.
Affected Version(s)
CryptoLib < 1.4.3
