ION-DTN versions prior to 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function. Unauthenticated remote attackers can exploit this by sending truncated SDNV values via UDP datagrams to the LTP link service input port. The vulnerability can trigger memory reads up to nine bytes past buffer boundaries and cause byte counter underflows. No authentication is required to exploit this flaw, making it accessible to any network-adjacent or remote attacker. The vulnerability has been patched in ION-DTN version 4.2.0. ION-DTN is NASA JPL's open-source implementation of the Delay-Tolerant Networking (DTN) protocol, commonly used in space communications infrastructure. A fix commit is available on GitHub along with a security advisory via GHSA-85pw-28vw-2jf7.