CVE-2026-21898
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, the CryptoAOSProcessSecurity function reads memory without valid bounds checking when parsing AOS frame hashes. This issue has been patched in version 1.4.3.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/21xxx/CVE-2026-21898.json, https://github.com/nasa/CryptoLib/releases/tag/v1.4.3, https://github.com/nasa/CryptoLib/security/advisories/GHSA-7ch6-2pmg-m853, https://nvd.nist.gov/vuln/detail/CVE-2026-21898
