Loading HuntDB...

GHSA-pg75-v6fp-8q59

GitHub Security Advisory

Keylime's registrar vulnerable to Denial-of-service attack via a single open connection

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

### Impact
Keylime `registrar` is prone to a simple denial of service attack in which an adversary opens a connection to the TLS port (by default, port `8891`) blocking further, legitimate connections. As long as the connection is open, the `registrar` is blocked and cannot serve any further clients (`agents` and `tenants`), which prevents normal operation. The problem does not affect the `verifier`.

### Patches
Users should upgrade to release 7.4.0

Affected Packages

PyPI keylime
Affected versions: 0 (fixed in 7.4.0)

Related CVEs

Key Information

GHSA ID
GHSA-pg75-v6fp-8q59
Published
August 1, 2023 8:16 PM
Last Modified
August 1, 2023 8:16 PM
CVSS Score
7.5 /10
Primary Ecosystem
PyPI
Primary Package
keylime
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 31, 2025 6:36 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.