GHSA-g9wh-3vrx-r7hg
GitHub Security Advisory
OctoRPKI crashes when processing GZIP bomb returned via malicious repository
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
OctoRPKI tries to load the entire contents of a repository in memory, and in the case of a GZIP bomb, unzip it in memory, making it possible to create a repository that makes OctoRPKI run out of memory (and thus crash).
## Patches
## For more information
If you have any questions or comments about this advisory email us at [email protected]
Affected Packages
Go
github.com/cloudflare/cfrpki
Affected versions:
0
(fixed in 1.4.0)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: September 17, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.