


Perceptive Security
SOC/SIEM Consultancy

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a…
Published:
9 January 2026 at 23:00:00
Alert date:
10 January 2026 at 13:10:58
Source:
nvd.nist.gov
CVE-2026-21897 affects NASA's CryptoLib, a software solution for securing spacecraft communications using CCSDS Space Data Link Security Protocol. The vulnerability exists in the Crypto_Config_Add_Gvcid_Managed_Parameters function prior to version 1.4.3, where improper boundary checking allows writing past the end of an array. This causes an out-of-bounds write that overwrites the gvcid_counter variable with arbitrary values, potentially affecting parameter lookup and registration logic. The issue impacts communications security between spacecraft running core Flight System (cFS) and ground stations. The vulnerability has been patched in version 1.4.3.
Technical details
Mitigation steps:
Affected products:
NASA CryptoLib
core Flight System
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-21897
https://github.com/nasa/CryptoLib/releases/tag/v1.4.3
https://github.com/nasa/CryptoLib/security/advisories/GHSA-9x7j-gx23-7m5r
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
