CVE-2026-21897 is an out-of-bounds write vulnerability affecting NASA's CryptoLib, a software solution for securing spacecraft communications using the CCSDS Space Data Link Security Protocol. Prior to version 1.4.3, the Crypto_Config_Add_Gvcid_Managed_Parameters function incorrectly validates input, allowing a write past the end of an array. This can corrupt the gvcid_counter variable, potentially disrupting parameter lookup and registration logic. The vulnerability has a CVSS score of 7.3 (HIGH), indicating a significant risk. It is remotely exploitable with low attack complexity and no user interaction required, potentially leading to low impacts on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage. The vulnerability has been patched in CryptoLib version 1.4.3.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.4.3CPE matchmatch criteria | cpe:2.3:a:nasa:cryptolib:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.