GHSA-g5gj-9ggf-9vmq
GitHub Security Advisory
Infinite certificate chain depth results in OctoRPKI running forever
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
OctoRPKI (github.com/cloudflare/cfrpki/cmd/octorpki) does not limit the depth of a certificate chain, allowing for a CA to create children in an ad-hoc fashion, thereby making tree traversal never end.
### For more information
If you have any questions or comments about this advisory email us at [email protected]
Affected Packages
Go
github.com/cloudflare/cfrpki
Affected versions:
0
(fixed in 1.4.0)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: September 11, 2025 6:35 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.