Intel

AIKIDO-2025-10731

github.com/yaronf/httpsign is vulnerable to Denial of Service (DoS)

Denial of Service (DoS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Oct 23, 2025

21

Low Risk

This Affects:

gogithub.com/yaronf/httpsign
0.0.1 - 0.3.2
Fixed in 0.3.3
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to denial of service (DoS) due to a flaw in the sign function when using ed25519 with a key that is not 64 bytes. Supplying such an invalid key triggers a panic, causing the application to crash and become unavailable.

Who does this affect?

You are affected if you are using a vulnerable version of the package.

Background info

github.com/yaronf/httpsign is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 0.3.2.

How to fix this

Upgrade the github.com/yaronf/httpsign library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform