spomky-labs/pki-framework is vulnerable to Uncontrolled Resource Consumption
75
High Risk
CertificationPathBuilder::assertPathCount() increments the path counter only when a produced path is appended, so recursive sub-calls that never reach a trust anchor process the whole subtree without hitting the MAX_PATHS bound. Mutually issuing intermediate certificates that chain to nothing enumerate every ordered sequence up to the maximum path length, and a few kilobytes of those certificates cost minutes of CPU during path building. The fix counts explored paths so the bound fires.
You are affected if you are using a version that falls within the vulnerable range and you build certification paths from peer supplied intermediate certificates.
spomky-labs/pki-framework is vulnerable to Uncontrolled Resource Consumption in versions 1.0.0 - 1.6.1.
Upgrade the spomky-labs/pki-framework library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.