Out-of-Bounds Read in CryptoLib Affects NASA's Core Flight System
CVE-2026-21899

4.7MEDIUM

Key Information:

Vendor

Nasa

Status
Vendor
CVE Published:
10 January 2026

What is CVE-2026-21899?

CryptoLib, a library ensuring secure communications for spacecraft utilizing the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP), was found to allow an out-of-bounds read due to improper input handling in its base64urlDecode function. Specifically, before version 1.4.3, the code did not validate the input length, leading to potential crashes when processing empty or NULL inputs. This vulnerability could affect essential operations in space missions, necessitating immediate action through the upgrade to version 1.4.3, where this issue has been rectified.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

CryptoLib < 1.4.3

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.