nasa has 3 CVEs on record. 1 was published in the last 90 days. The median CVSS is 5.5 (medium). Most affected products: core_flight_system (2), CryptoLib (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.5
- Publish → KEV
- —
- Last 90 days
- 1 prev 2
Worst active — by depth score
CVE-2026-79954High· 8.7NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path48CVE-2026-5475Medium· 5.5A vulnerability was determined in NASA cFS up to 7.0.030CVE-2026-5476Medium· 4.6A vulnerability was identified in NASA cFS up to 7.0.0 on 32-bit25
nasa vulnerabilities
CVEs affecting nasa, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-79954High· 8.7NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path
NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiver selects the Security Association used for SDLS processing solely from the SPI field inside the incoming frame, but…
CVE-2026-5476Medium· 4.6A vulnerability was identified in NASA cFS up to 7.0.0 on 32-bit
A vulnerability was identified in NASA cFS up to 7.0.0 on 32-bit. Affected is the function CFE_TBL_ValidateCodecLoadSize of the file cfe/modules/tbl/fsw/src/cfe_tbl_passthru_codec.c. The manipulation leads to integer overflow. The comple…
CVE-2026-5475Medium· 5.5A vulnerability was determined in NASA cFS up to 7.0.0
A vulnerability was determined in NASA cFS up to 7.0.0. This impacts the function CFE_SB_TransmitMsg of the file cfe_sb_priv.c of the component CCSDS Header Size Handler. Executing a manipulation can lead to memory corruption. The projec…