Disclosures
NASA · CryptoLib
Out-of-Bounds Read in KMC AEAD Encrypt Metadata Parsing via Flawed strtok Pattern
SecMateSECMATE-2025-0007
VendorNASA
ProductCryptoLib
ReportedNovember 29, 2025
FixedJanuary 6, 2026
PublishedJanuary 9, 2026
AdvisoryGHSA-8w3h-q8jm-3chq
An out-of-bounds heap read vulnerability in cryptography_aead_encrypt() with the same root cause as the cryptography_encrypt() vulnerability - flawed strtok iteration pattern at lines 1336, 1340, and 1344. This is a copy-pasted code pattern that introduces the same bug in the AEAD encrypt function.