---
id: CVE-2026-79954
title: >-
  NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the
  Telecommand (TC) receive path
summary: >-
  NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the
  Telecommand (TC) receive path. The receiver selects the Security Association
  used for SDLS processing solely from the SPI field inside the incoming frame,
  but…
severity: high
cvss: 8.7
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-306
vendor: NASA
product: CryptoLib
affected:
  - CryptoLib 1.5.0
published: '2026-09-18'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T20:17:23.097'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-79954'
references:
  - url: 'https://fluidattacks.com/advisories/linkin'
    label: help@fluidattacks.com
  - url: 'https://github.com/nasa/CryptoLib'
    label: help@fluidattacks.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-18T19:58:38.011606Z'
cvssSource: cna
epss: 0.00564
epssPercentile: 0.44564
ingestedAt: '2026-09-18T01:33:24.267Z'
---

## Overview

NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiver selects the Security Association used for SDLS processing solely from the SPI field inside the incoming frame, but it does not verify that the selected SA is authorized for the frame's GVCID.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
