Skip to main content
Disclosures

NASA · CryptoLib

Memory Leak in KMC Encrypt Function Leads to Resource Exhaustion

6.3medium
SecMateSECMATE-2025-0006
VendorNASA
ProductCryptoLib
VectorCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Timeline
Reported
Nov 29, 2025
Fixed
Jan 6, 2026
Published
Jan 9, 2026
Summary

The cryptography_encrypt() function allocates multiple buffers for HTTP requests and JSON parsing that are never freed on any code path. Each call leaks approximately 400 bytes of memory. Sustained traffic can gradually exhaust available memory.

What's hidden in yours?

Find out