Intel

AIKIDO-2026-406014

spomky-labs/pki-framework is vulnerable to Uncontrolled Resource Consumption

Uncontrolled Resource ConsumptionGHSA-34rx-vp5j-q2wr Published 5 days ago

59

Medium Risk

This Affects:

PHPspomky-labs/pki-framework
0.0.1 - 1.6.1
Fixed in 1.6.2
Are you affected? Scan for Free

TL;DR

PolicyTree has no size limit. Policy mappings grow the expected policy set to a size chosen in the certificate, and each later certificate adds that many child nodes per existing node without checking for duplicate siblings. A signed chain from a delegated sub-CA grows the tree multiplicatively with path depth and exhausts memory after trust checks pass. The fix bounds the policy tree and removes duplicate nodes.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you validate certification paths that use certificate policies with a delegated sub-CA.

Background info

spomky-labs/pki-framework is vulnerable to Uncontrolled Resource Consumption in versions 0.0.1 - 1.6.1.

How to fix this

Upgrade the spomky-labs/pki-framework library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform