{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-02T12:34:51.151","vulnerabilities":[{"cve":{"id":"CVE-2026-22697","sourceIdentifier":"security-advisories@github.com","published":"2026-01-10T01:16:19.160","lastModified":"2026-06-17T10:20:15.223","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, CryptoLib’s KMC crypto service integration is vulnerable to a heap buffer overflow when decoding Base64-encoded ciphertext/cleartext fields returned by the KMC service. The decode destination buffer is sized using an expected output length (len_data_out), but the Base64 decoder writes output based on the actual Base64 input length and does not enforce any destination size limit. An oversized Base64 string in the KMC JSON response can cause out-of-bounds writes on the heap, resulting in process crash and potentially code execution under certain conditions. This issue has been patched in version 1.4.3."},{"lang":"es","value":"CryptoLib proporciona una solución únicamente de software utilizando el Protocolo de Seguridad de Enlace de Datos Espaciales CCSDS - Procedimientos Extendidos (SDLS-EP) para asegurar las comunicaciones entre una nave espacial que ejecuta el Sistema de Vuelo central (cFS) y una estación terrestre. Antes de la versión 1.4.3, la integración del servicio criptográfico KMC de CryptoLib es vulnerable a un desbordamiento de búfer de pila al decodificar campos de texto cifrado/texto claro codificados en Base64 devueltos por el servicio KMC. El búfer de destino de decodificación se dimensiona utilizando una longitud de salida esperada (len_data_out), pero el decodificador Base64 escribe la salida basándose en la longitud real de la entrada Base64 y no impone ningún límite de tamaño de destino. Una cadena Base64 sobredimensionada en la respuesta JSON del KMC puede causar escrituras fuera de límites en la pila, lo que resulta en un fallo del proceso y potencialmente la ejecución de código bajo ciertas condiciones. Este problema ha sido parcheado en la versión 1.4.3."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"nasa","product":"CryptoLib","versions":[{"version":"< 1.4.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-01-13T21:48:35.288004Z","id":"CVE-2026-22697","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-122"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:nasa:cryptolib:*:*:*:*:*:*:*:*","versionEndExcluding":"1.4.3","matchCriteriaId":"AE1BE91E-2901-42AF-BC66-762CFA7A2582"}]}]}],"references":[{"url":"https://github.com/nasa/CryptoLib/releases/tag/v1.4.3","source":"security-advisories@github.com","tags":["Release Notes"]},{"url":"https://github.com/nasa/CryptoLib/security/advisories/GHSA-qjx3-83jh-2jc4","source":"security-advisories@github.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://github.com/nasa/CryptoLib/security/advisories/GHSA-qjx3-83jh-2jc4","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Vendor Advisory"]}]}}]}