CVE-2021-3910

HIGH7.5EPSS 0.56%

NUL character in ROA causes OctoRPKI to crash

Published: 11/10/2021Modified: 4/15/2026
Also known as:GHSA-5mxh-2qfv-4g7jGO-2022-0251

Description

OctoRPKI crashes when encountering a repository that returns an invalid ROA (just an encoded `NUL` (`\0`) character). ## Patches ## For more information If you have any questions or comments about this advisory email us at [email protected]

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References (8)