NASA's vulnerability footprint centers on a specialized portfolio of mission-critical and ground-support software spanning cryptographic libraries, flight systems, telemetry processing, and visualization platforms that underpin aerospace operations and scientific data handling. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur across products such as CryptoLib, Core Flight System, AIT Core, OpenMCT, and CFITSIO through weakness classes including out-of-bounds writes and reads, heap-based buffer overflows, untrusted deserialization, and cross-site scripting that reflect both low-level memory safety demands and web interface exposure. The prominence of memory-safety and input-validation flaws underscores the risk inherent in mission-critical software that operates in high-assurance environments and often integrates with legacy or constrained systems where patching cycles are protracted. Defenders responsible for aerospace, earth science, or space-agency infrastructure should treat this vendor's advisories with priority and maintain visibility into supply-chain dependencies on these libraries and systems; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nasa over time
Signals from CVEs in this vendor scope (60 CVEs).
60 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-1010060CRITICAL NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow. The impact is: arbitrary code execution. The component is: over 40 source code files were changed. The attack vector is: | Jul 16, 2019 | 9.8 | 33 | NO | NO |
CVE-2026-41144CRITICAL F´ (F Prime) is a framework that enables development and deployment of spaceflight and other embedded software applications. Prior to version 4.2.0, the bounds check byteOffset + d | Apr 22, 2026 | 9.8 | 31 | NO | NO |
CVE-2025-54878HIGH CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running | Aug 11, 2025 | 8.6 | 30 | NO | NO |
CVE-2025-25373CRITICAL The Memory Management Module of NASA cFS (Core Flight System) Aquila has insecure permissions, which can be exploited to gain an RCE on the platform. | Mar 25, 2025 | 9.8 | 30 | NO | NO |
CVE-2024-55030CRITICAL A command injection vulnerability in the Command Dispatcher Service of NASA Fprime v3.4.3 allows attackers to execute arbitrary commands. | Mar 25, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-64096HIGH CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running | Oct 30, 2025 | 8.8 | 29 | NO | NO |
CVE-2018-3847HIGH Multiple exploitable buffer overflow vulnerabilities exist in image parsing functionality of the CFITSIO library version 3.42. Specially crafted images parsed via the library, can | Aug 1, 2018 | 8.8 | 29 | NO | NO |
CVE-2018-3849HIGH In the ffghtb function in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can del | Apr 16, 2018 | 8.8 | 29 | NO | NO |
CVE-2018-3846HIGH In the ffgphd and ffgtkn functions in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data. An atta | Apr 16, 2018 | 8.8 | 29 | NO | NO |
CVE-2026-5474HIGH A vulnerability was found in NASA cFS up to 7.0.0. This affects the function CFE_MSG_GetSize of the file apps/to_lab/fsw/src/to_lab_passthru_encode.c of the component CCSDS Packet | Apr 3, 2026 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (60 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nasa.
Media articles that mention a CVE ID that affects a product developed by Nasa — matched by CVE ID, not by vendor name.