ryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, the cryptography_encrypt() function allocates multiple buffers for HTTP requests and JSON parsing that are never freed on any code path. Each call leaks approximately 400 bytes of memory. Sustained traffic can gradually exhaust available memory. This issue has been patched in version 1.4.3.
| Link | Resource |
|---|---|
| https://github.com/nasa/CryptoLib/commit/2372efd3da1ccb226b4297222e25f41ecc84821d | Patch |
| https://github.com/nasa/CryptoLib/releases/tag/v1.4.3 | Release Notes |
| https://github.com/nasa/CryptoLib/security/advisories/GHSA-r3wg-g8xv-gxvf | Exploit Vendor Advisory |
| https://github.com/nasa/CryptoLib/security/advisories/GHSA-r3wg-g8xv-gxvf | Exploit Vendor Advisory |
16 Jan 2026, 16:44
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/nasa/CryptoLib/commit/2372efd3da1ccb226b4297222e25f41ecc84821d - Patch | |
| References | () https://github.com/nasa/CryptoLib/releases/tag/v1.4.3 - Release Notes | |
| References | () https://github.com/nasa/CryptoLib/security/advisories/GHSA-r3wg-g8xv-gxvf - Exploit, Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
| CPE | cpe:2.3:a:nasa:cryptolib:*:*:*:*:*:*:*:* | |
| First Time |
Nasa
Nasa cryptolib |
13 Jan 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/nasa/CryptoLib/security/advisories/GHSA-r3wg-g8xv-gxvf - |
10 Jan 2026, 01:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2026-01-10 01:16
Updated : 2026-01-16 16:44
NVD link : CVE-2026-22024
Mitre link : CVE-2026-22024
CVE.ORG link : CVE-2026-22024
JSON object : View
Missing Release of Memory after Effective Lifetime