PT-2026-2132 · Cryptolib · Cryptolib

Enitmar

+1

·

Published

2026-01-10

·

Updated

2026-04-05

·

CVE-2026-22024

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions CryptoLib versions prior to 1.4.3
Description CryptoLib is a software-only solution utilizing the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, the cryptography encrypt() function allocates multiple buffers for HTTP requests and JSON parsing that are not freed, resulting in a memory leak. Each call to the function leaks approximately 400 bytes of memory, and sustained traffic can gradually exhaust available memory.
Recommendations Versions prior to 1.4.3 should be updated to version 1.4.3 or later.

Exploit

Fix

Memory Leak

Weakness Enumeration

Related Identifiers

CVE-2026-22024
GHSA-R3WG-G8XV-GXVF

Affected Products

Cryptolib