QID 980112
QID 980112: Go (go) Security Update for github.com/cloudflare/cfrpki (GHSA-g9wh-3vrx-r7hg)
OctoRPKI tries to load the entire contents of a repository in memory, and in the case of a GZIP bomb, unzip it in memory, making it possible to create a repository that makes OctoRPKI run out of memory (and thus crash).
## Patches
## For more information
If you have any questions or comments about this advisory email us at [email protected]
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-g9wh-3vrx-r7hg for updates pertaining to this vulnerability.
Vendor References
- GHSA-g9wh-3vrx-r7hg -
github.com/advisories/GHSA-g9wh-3vrx-r7hg
CVEs related to QID 980112
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-g9wh-3vrx-r7hg | github.com/cloudflare/cfrpki |
|