Browse all 39 CVE security advisories affecting NASA. AI-powered Chinese analysis, POCs, and references for each vulnerability.
NASA operates as the United States’ civilian space agency, managing complex aerospace research, satellite communications, and planetary exploration missions. Its extensive digital infrastructure includes legacy control systems, web-facing public portals, and internal enterprise networks, creating a broad attack surface. Historically, vulnerabilities within its ecosystem have frequently involved remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from outdated software components or misconfigured web applications. While no catastrophic data breaches have publicly compromised critical mission-critical telemetry, the agency has faced scrutiny over data privacy and system integrity. The presence of thirty-four recorded CVEs highlights ongoing challenges in maintaining security across diverse, specialized technical environments. Continuous patching and rigorous access controls remain essential to protect sensitive scientific data and ensure the reliability of critical space operations against evolving cyber threats.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-29912 | CryptoLib Has Heap Buffer Overflow Due to Unsigned Integer Underflow in Crypto_TC_ProcessSecurity — CryptoLib CWE-122 | 9.8 | - | 2025-03-17 |
| CVE-2025-29911 | CryptoLib Has Heap Buffer Overflow in Crypto_AOS_ProcessSecurity Function — CryptoLib CWE-122 | 9.8 | - | 2025-03-17 |
| CVE-2025-29910 | CryptoLib's crypto_handle_incrementing_nontransmitted_counter Function has Memory Leak — CryptoLib CWE-401 | 7.5 | - | 2025-03-17 |
| CVE-2025-29909 | CryptoLib's Crypto_TC_ApplySecurity() Has a Heap Buffer Overflow Vulnerability — CryptoLib CWE-191 | 9.8 | - | 2025-03-17 |
| CVE-2022-23054 | Openmct XSS via the “Summary Widget” — openmct CWE-79 | 6.1 | Medium | 2022-02-20 |
| CVE-2022-23053 | Openmct XSS via the “Condition Widget” — openmct CWE-79 | 6.1 | Medium | 2022-02-20 |
| CVE-2022-22126 | Openmct XSS via the “Web Page” element — openmct CWE-79 | 6.1 | Medium | 2022-02-20 |
| CVE-2019-1010060 | NASA CFITSIO 缓冲区错误漏洞 — CFITSIO | 9.8 | - | 2019-07-16 |
| CVE-2018-3847 | CFITSIO library 缓冲区错误漏洞 — CFITSIO | 8.8 | - | 2018-08-01 |
This page lists every published CVE security advisory associated with NASA. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.