GHSA-pg75-v6fp-8q59
GitHub Security Advisory
Keylime's registrar vulnerable to Denial-of-service attack via a single open connection
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
### Impact
Keylime `registrar` is prone to a simple denial of service attack in which an adversary opens a connection to the TLS port (by default, port `8891`) blocking further, legitimate connections. As long as the connection is open, the `registrar` is blocked and cannot serve any further clients (`agents` and `tenants`), which prevents normal operation. The problem does not affect the `verifier`.
### Patches
Users should upgrade to release 7.4.0
Affected Packages
PyPI
keylime
Affected versions:
0
(fixed in 7.4.0)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: July 31, 2025 6:36 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.