6.3medium
SecMateSECMATE-2025-0006
VendorNASA
ProductCryptoLib
VectorCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
AdvisoryGHSA-r3wg-g8xv-gxvf
Timeline
Reported
Nov 29, 2025
Fixed
Jan 6, 2026
Published
Jan 9, 2026
Summary
The cryptography_encrypt() function allocates multiple buffers for HTTP requests and JSON parsing that are never freed on any code path. Each call leaks approximately 400 bytes of memory. Sustained traffic can gradually exhaust available memory.