Intel

AIKIDO-2025-10731

github.com/yaronf/httpsign is vulnerable to Denial of Service (DoS)

Denial of Service (DoS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Oct 23, 2025

21

Low Risk

This Affects:

gogithub.com/yaronf/httpsign
0.0.1 - 0.3.2
Fixed in 0.3.3
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to denial of service (DoS) due to a flaw in the sign function when using ed25519 with a key that is not 64 bytes. Supplying such an invalid key triggers a panic, causing the application to crash and become unavailable.

Who does this affect?

You are affected if you are using a vulnerable version of the package.

Background info

github.com/yaronf/httpsign is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 0.3.2.

How to fix this

Upgrade the github.com/yaronf/httpsign library to the patch version.