CVE-2026-21899: CryptoLib has an out-of-bounds read and crash vulnerability when decoding an empty Base64url string
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, in base64urlDecode, padding-stripping dereferences input[inputLen - 1] before checking that inputLen > 0 or that input != NULL. For inputLen == 0, this becomes an OOB read at input[-1], potentially crashing the process. If input == NULL and inputLen == 0, it dereferences NULL - 1. This issue has been patched in version 1.4.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21899?
CVE-2026-21899 has been classified with a medium severity rating due to its potential impact on data integrity during communication.
Which versions of CryptoLib are affected by CVE-2026-21899?
CVE-2026-21899 affects versions of CryptoLib prior to 1.4.3.
How do I fix CVE-2026-21899?
To fix CVE-2026-21899, you should upgrade CryptoLib to version 1.4.3 or later.
What kind of vulnerability is CVE-2026-21899 associated with?
CVE-2026-21899 is associated with a cryptographic vulnerability in base64url decoding and padding.
What protocols are impacted by CVE-2026-21899?
CVE-2026-21899 impacts the CCSDS Space Data Link Security Protocol - Extended Procedures used for spacecraft communication.