CVE-2026-22024
Each call leaks approximately 400 bytes of memory.
Does this matter?
Lower severity and a low EPSS score (0.49%). Track it; it rarely justifies an emergency change on its own.
Description
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, the cryptography_encrypt() function allocates multiple buffers for HTTP requests and JSON parsing that are never freed on any code path. Each call leaks approximately 400 bytes of memory. Sustained traffic can gradually exhaust available memory. This issue has been patched in version 1.4.3.
- CVSS 4.0
- 6.3 MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.49% probability · 40th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-401
- Affected
- nasa/cryptolib
- Source
- security-advisories@github.com
References
- https://github.com/nasa/CryptoLib/commit/2372efd3da1ccb226b4297222e25f41ecc84821dPatch
- https://github.com/nasa/CryptoLib/releases/tag/v1.4.3Release Notes
- https://github.com/nasa/CryptoLib/security/advisories/GHSA-r3wg-g8xv-gxvfExploit, Vendor Advisory
- https://github.com/nasa/CryptoLib/security/advisories/GHSA-r3wg-g8xv-gxvfExploit, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.