spomky-labs/pki-framework is vulnerable to Uncontrolled Resource Consumption
75
High Risk
DER decoder loops accumulate untrusted continuation octets without bounds, including decodeLongFormTag() in Identifier.php and the sub-identifier loops in ObjectIdentifier.php and RelativeOID.php. Each step rebuilds a BigInteger, so a long run of octets costs work quadratic in its length during certificate parsing, before any signature is checked. A few kilobytes of crafted DER cost minutes of CPU. The fix bounds the octet counts and rejects oversized fields.
You are affected if you are using a version that falls within the vulnerable range and you decode untrusted ASN.1/DER, certificates, CSRs, or PEM data.
spomky-labs/pki-framework is vulnerable to Uncontrolled Resource Consumption in versions 1.0.0 - 1.6.1.
Upgrade the spomky-labs/pki-framework library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.