CVE-2021-3908: Infinite certificate chain depth results in OctoRPKI running forever
OctoRPKI (github.com/cloudflare/cfrpki/cmd/octorpki) does not limit the depth of a certificate chain, allowing for a CA to create children in an ad-hoc fashion, thereby making tree traversal never end.
For more information If you have any questions or comments about this advisory email us at security@cloudflare.com
Other sources
OctoRPKI does not limit the depth of a certificate chain, allowing for a CA to create children in an ad-hoc fashion, thereby making tree traversal never end.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-3908?
The severity of CVE-2021-3908 is high with a CVSS score of 7.5.
How does CVE-2021-3908 affect OctoRPKI?
CVE-2021-3908 affects OctoRPKI by allowing a CA to create children in an ad-hoc fashion, causing tree traversal to never end.
Which versions of OctoRPKI are affected by CVE-2021-3908?
OctoRPKI versions up to and excluding 1.4.0 are affected by CVE-2021-3908.
How can I fix CVE-2021-3908 in OctoRPKI?
To fix CVE-2021-3908 in OctoRPKI, upgrade to version 1.4.0 or later.
Are there any additional resources for CVE-2021-3908?
Yes, you can find additional resources for CVE-2021-3908 at the following links: [GitHub Security Advisory](https://github.com/cloudflare/cfrpki/security/advisories/GHSA-g5gj-9ggf-9vmq) and [NVD](https://nvd.nist.gov/vuln/detail/CVE-2021-3908).