PT-2026-2134 · Cryptolib+1 · Cryptolib+1

Enitmar

+1

·

Published

2026-01-10

·

Updated

2026-01-10

·

CVE-2026-22026

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions CryptoLib versions prior to 1.4.3
Description CryptoLib is a software solution utilizing the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) for secure communication between a spacecraft and a ground station. The write callback function within the KMC crypto service client, prior to version 1.4.3, does not adequately limit the size of reallocated response buffers. This allows a malicious KMC server to send arbitrarily large HTTP responses, leading to excessive memory allocation and potential process termination. The vulnerable component is the libcurl function used for handling HTTP responses. The write callback function is specifically affected.
Recommendations Versions prior to 1.4.3 should be updated to version 1.4.3 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-22026
GHSA-W9CM-Q69W-34X7

Affected Products

Cryptolib
Libcurl