Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

NASA — Vulnerabilities & Security Advisories 39

Browse all 39 CVE security advisories affecting NASA. AI-powered Chinese analysis, POCs, and references for each vulnerability.

NASA operates as the United States’ civilian space agency, managing complex aerospace research, satellite communications, and planetary exploration missions. Its extensive digital infrastructure includes legacy control systems, web-facing public portals, and internal enterprise networks, creating a broad attack surface. Historically, vulnerabilities within its ecosystem have frequently involved remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from outdated software components or misconfigured web applications. While no catastrophic data breaches have publicly compromised critical mission-critical telemetry, the agency has faced scrutiny over data privacy and system integrity. The presence of thirty-four recorded CVEs highlights ongoing challenges in maintaining security across diverse, specialized technical environments. Continuous patching and rigorous access controls remain essential to protect sensitive scientific data and ensure the reliability of critical space operations against evolving cyber threats.

CVE ID Title CVSS Severity Published
CVE-2026-72579 NASA HyperCP - OS Command Injection via Malicious HTTP Response from Data Server — HyperCP CWE-78 7.5 High 2026-08-10
CVE-2026-72577 NASA fprime-gds - Missing Authentication and Path Traversal Enable Unauthenticated RCE and Spacecraft Command Injection — fprime-gds CWE-306 9.8 Critical 2026-08-10
CVE-2026-18064 NASA Core Flight System (cFS) Health & Safety (HS) Application NULL Pointer Dereference — Core Flight System (cFS) Health & Safety (HS) Application CWE-476 7.5 High 2026-07-30
CVE-2026-15352 NASA Core Flight System (cFS) Health & Safety (HS) Application NULL Pointer Dereference — Core Flight System (cFS) Health & Safety (HS) Application CWE-476 7.5 High 2026-07-16
CVE-2018-25367 NASA openVSP 3.16.1 Denial of Service via Buffer Overflow — openVSP CWE-120 6.2 Medium 2026-05-25
CVE-2026-41144 F´ (F Prime) has Integer Overflow in FileUplink — fprime CWE-190 - - 2026-04-21
CVE-2026-5476 NASA cFS cfe_tbl_passthru_codec.c CFE_TBL_ValidateCodecLoadSize integer overflow — cFS CWE-190 4.6 Medium 2026-04-03
CVE-2026-5475 NASA cFS CCSDS Header Size cfe_sb_priv.c CFE_SB_TransmitMsg memory corruption — cFS CWE-119 5.5 Medium 2026-04-03
CVE-2026-5474 NASA cFS CCSDS Packet Header to_lab_passthru_encode.c CFE_MSG_GetSize heap-based overflow — cFS CWE-122 6.3 Medium 2026-04-03
CVE-2026-5473 NASA cFS Pickle pickle.load deserialization — cFS CWE-502 4.5 Medium 2026-04-03
CVE-2026-22697 CryptoLib Has Heap Buffer Overflow Vulnerability in KMC Base64 Decode Handling (KMC JSON base64ciphertext/base64cleartext) — CryptoLib CWE-122 7.5 High 2026-01-10
CVE-2026-22027 CryptoLib Vulnerable to Heap Buffer Overflow in MariaDB SA Hexstring Conversion — CryptoLib CWE-122 9.8 - 2026-01-10
CVE-2026-22026 CryptoLib Unbounded Memory Allocation in KMC HTTP Response Handler Allows Resource Exhaustion — CryptoLib CWE-789 7.5 - 2026-01-10
CVE-2026-22025 CryptoLib Memory Leak on HTTP Error Response in KMC Client — CryptoLib CWE-401 - - 2026-01-10
CVE-2026-22024 CryptoLib Memory Leak in KMC Encrypt Function Leads to Resource Exhaustion — CryptoLib CWE-401 7.5 - 2026-01-10
CVE-2026-22023 CryptoLib Has Out-of-Bounds Read in KMC AEAD Encrypt Metadata Parsing via Flawed strtok Pattern — CryptoLib CWE-125 9.1 - 2026-01-10
CVE-2026-21900 CryptoLib Has Out-of-Bounds Read in KMC Encrypt Metadata Parsing via Flawed strtok Pattern — CryptoLib CWE-125 9.1 - 2026-01-10
CVE-2026-21899 CryptoLib has an out-of-bounds read and crash vulnerability when decoding an empty Base64url string — CryptoLib CWE-125 4.7 Medium 2026-01-10
CVE-2026-21898 CryptoLib Has Out-of-bounds Read in Crypto_AOS_ProcessSecurity — CryptoLib CWE-125 8.2 High 2026-01-10
CVE-2026-21897 CryptoLib Has Out-of-Bounds Write in Crypto_Config_Add_Gvcid_Managed_Parameters — CryptoLib CWE-787 7.3 High 2026-01-10
CVE-2025-64096 CryptoLib vulnerable to Stack Buffer Overflow in Crypto_Key_Update due to missing TLV length check — CryptoLib CWE-121 9.8AI Critical AI 2025-10-30
CVE-2025-59534 CryptoLib command Injection vulnerability in initialize_kerberos_keytab_file_login() — CryptoLib CWE-78 7.3 High 2025-09-23
CVE-2025-54878 Heap Buffer Overflow in NASA CryptoLib 1.4.0 `Crypto_TC_Check_IV_Setup` — CryptoLib CWE-122 8.6 High 2025-08-11
CVE-2025-46675 CryptoLib 安全漏洞 — CryptoLib CWE-913 3.5 Low 2025-04-27
CVE-2025-46674 CryptoLib 安全漏洞 — CryptoLib CWE-489 3.5 Low 2025-04-27
CVE-2025-46672 CryptoLib 安全漏洞 — CryptoLib CWE-252 3.5 Low 2025-04-27
CVE-2025-46673 CryptoLib 安全漏洞 — CryptoLib CWE-913 4.9 Medium 2025-04-27
CVE-2025-30356 Heap Buffer Overflow via Incomplete Length Check in `Crypto_TC_ApplySecurity` — CryptoLib CWE-191 9.8AI Critical AI 2025-04-01
CVE-2025-30216 CryptoLib Has Heap Overflow in Crypto_TM_ProcessSecurity due to Unchecked Secondary Header Length — CryptoLib CWE-122 9.4 Critical 2025-03-25
CVE-2025-29913 CryptoLib's Crypto_TC_Prep_AAD Has Buffer Overflow Due to Integer Underflow — CryptoLib CWE-125 9.8 - 2025-03-17

This page lists every published CVE security advisory associated with NASA. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.