PT-2026-2133 · Cryptolib · Cryptolib

Enitmar

+1

·

Published

2026-01-10

·

Updated

2026-01-10

·

CVE-2026-22025

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions CryptoLib versions prior to 1.4.3
Description CryptoLib is a software solution utilizing the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft and a ground station. Before version 1.4.3, the cryptography encrypt() and cryptography decrypt() functions do not free allocated buffers when the KMC server returns a non-200 HTTP status code. Each failed request results in a memory leak of approximately 467 bytes, potentially leading to memory exhaustion with repeated failures. The issue occurs when interacting with the KMC server.
Recommendations Update to CryptoLib version 1.4.3 or later.

Exploit

Fix

Memory Leak

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2026-22025
GHSA-H74X-VWWR-MM5G

Affected Products

Cryptolib