<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/">
  <channel>
    <title>NASA CVEs · CVE Brief</title>
    <link>https://cvebrief.com/archive/cves/vendor/nasa/</link>
    <atom:link href="https://cvebrief.com/feeds/vendor/nasa.xml" rel="self" type="application/rss+xml"/>
    <description>High and critical NASA vulnerabilities covered by CVE Brief, with independent analyst commentary.</description>
    <language>en-us</language>
    <lastBuildDate>Sat, 19 Sep 2026 12:00:00 GMT</lastBuildDate>
    <item>
      <title>CVE-2026-79954 · CVSS 8.7 · CryptoLib</title>
      <link>https://cvebrief.com/cve/cve-2026-79954/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-nasa-CVE-2026-79954</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/nasa.png" medium="image" type="image/png"/>
      <pubDate>Sat, 19 Sep 2026 12:00:00 GMT</pubDate>
      <description>NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-82801 · CVSS 7.3 · earthdata-search</title>
      <link>https://cvebrief.com/cve/cve-2026-82801/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-nasa-CVE-2026-82801</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/nasa.png" medium="image" type="image/png"/>
      <pubDate>Tue, 01 Sep 2026 12:00:00 GMT</pubDate>
      <description>A vulnerability was detected in NASA earthdata-search 1.0.0. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-82478 · CVSS 7.3 · Trick</title>
      <link>https://cvebrief.com/cve/cve-2026-82478/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-nasa-CVE-2026-82478</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/nasa.png" medium="image" type="image/png"/>
      <pubDate>Mon, 31 Aug 2026 12:00:00 GMT</pubDate>
      <description>A vulnerability was determined in NASA Trick 19.6.0. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-82480 · CVSS 7.4 · cFS</title>
      <link>https://cvebrief.com/cve/cve-2026-82480/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-nasa-CVE-2026-82480</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/nasa.png" medium="image" type="image/png"/>
      <pubDate>Sun, 30 Aug 2026 12:00:00 GMT</pubDate>
      <description>A security flaw has been discovered in NASA cFS up to 7.0.1. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-67973 · CVSS 7.5 · cFS</title>
      <link>https://cvebrief.com/cve/cve-2026-67973/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-nasa-CVE-2026-67973</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/nasa.png" medium="image" type="image/png"/>
      <pubDate>Thu, 27 Aug 2026 12:00:00 GMT</pubDate>
      <description>An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-67974 · CVSS 7.5 · cFS (Core Flight System)</title>
      <link>https://cvebrief.com/cve/cve-2026-67974/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-nasa-CVE-2026-67974</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/nasa.png" medium="image" type="image/png"/>
      <pubDate>Thu, 27 Aug 2026 12:00:00 GMT</pubDate>
      <description>A parser boundary flaw in the Software Bus Network (SBN) application&apos;s peer subscription message handling in NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via sending a crafted packet. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-67975 · CVSS 7.5 · cFS (Core Flight System)</title>
      <link>https://cvebrief.com/cve/cve-2026-67975/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-nasa-CVE-2026-67975</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/nasa.png" medium="image" type="image/png"/>
      <pubDate>Wed, 12 Aug 2026 12:00:00 GMT</pubDate>
      <description>Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add/remove subscription commands. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-72577 · CVSS 9.8 · fprime-gds</title>
      <link>https://cvebrief.com/cve/cve-2026-72577/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-nasa-CVE-2026-72577</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/nasa.png" medium="image" type="image/png"/>
      <pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate>
      <description>The NASA fprime-gds application fails to implement authentication on its Flask-based endpoints, allowing unauthenticated remote attackers to execute arbitrary code and issue commands to spacecraft. Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-72579 · CVSS 7.5 · HyperCP</title>
      <link>https://cvebrief.com/cve/cve-2026-72579/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-nasa-CVE-2026-72579</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/nasa.png" medium="image" type="image/png"/>
      <pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate>
      <description>An OS command injection vulnerability in NASA HyperCP (main branch) allows a network-adjacent attacker who can intercept or spoof responses from oceandata Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-21897 · CVSS 7.3 · CryptoLib</title>
      <link>https://cvebrief.com/cve/cve-2026-21897/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-nasa-CVE-2026-21897</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/nasa.png" medium="image" type="image/png"/>
      <pubDate>Sat, 10 Jan 2026 12:00:00 GMT</pubDate>
      <description>CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-21898 · CVSS 8.2 · CryptoLib</title>
      <link>https://cvebrief.com/cve/cve-2026-21898/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-nasa-CVE-2026-21898</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/nasa.png" medium="image" type="image/png"/>
      <pubDate>Sat, 10 Jan 2026 12:00:00 GMT</pubDate>
      <description>CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-22697 · CVSS 7.5 · CryptoLib</title>
      <link>https://cvebrief.com/cve/cve-2026-22697/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-nasa-CVE-2026-22697</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/nasa.png" medium="image" type="image/png"/>
      <pubDate>Sat, 10 Jan 2026 12:00:00 GMT</pubDate>
      <description>CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2025-64096 · CVSS 8.8 · CryptoLib</title>
      <link>https://cvebrief.com/cve/cve-2025-64096/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-nasa-CVE-2025-64096</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/nasa.png" medium="image" type="image/png"/>
      <pubDate>Thu, 30 Oct 2025 12:00:00 GMT</pubDate>
      <description>CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2025-59534 · CVSS 7.3 · CryptoLib</title>
      <link>https://cvebrief.com/cve/cve-2025-59534/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-nasa-CVE-2025-59534</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/nasa.png" medium="image" type="image/png"/>
      <pubDate>Tue, 23 Sep 2025 12:00:00 GMT</pubDate>
      <description>CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2025-54878 · CVSS 8.6 · CryptoLib</title>
      <link>https://cvebrief.com/cve/cve-2025-54878/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-nasa-CVE-2025-54878</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/nasa.png" medium="image" type="image/png"/>
      <pubDate>Mon, 11 Aug 2025 12:00:00 GMT</pubDate>
      <description>CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
  </channel>
</rss>
