openmls is vulnerable to Denial of Service (DoS)
53
Medium Risk
When decoding an extension list, each extension is checked for duplicate types by linearly scanning every previously accepted extension, giving quadratic time in the number of extensions. Because extension lists are decoded from untrusted MLS objects before authentication, supplying a vector with many distinct extension types forces excessive CPU work. A moderately sized input can take seconds to deserialize, enabling a denial of service against applications parsing such objects. The fix replaces the linear scan with an efficient duplicate check.
You are affected if you are using a version that falls within the vulnerable range and your application deserializes untrusted MLS objects containing extension lists on openmls between 0.6.0 and 0.8.1 without size or rate limits.
openmls is vulnerable to Denial of Service (DoS) in versions 0.6.0 - 0.8.1.
Upgrade the openmls library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.