spomky-labs/pki-framework is vulnerable to Improper Certificate Validation
74
High Risk
IPv6Address::octets() and IPv4Address::octets() split their input by delimiter and use the resulting octet count instead of validating the address family. An iPAddress name constraint in compressed IPv6 notation produces eight octets, which the library then uses as an IPv4 address plus subnet mask, and out-of-range values are truncated modulo 256. A permittedSubtrees entry such as 2001:db8:: allows the entire IPv4 address space and drops the intended IPv6 restriction. The fix validates the address family and rejects malformed iPAddress values.
You are affected if you are using a version that falls within the vulnerable range and you rely on iPAddress name constraints when validating certification paths.
spomky-labs/pki-framework is vulnerable to Improper Certificate Validation in versions 1.0.0 - 1.6.1.
Upgrade the spomky-labs/pki-framework library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.