Medium severity5.4NVD Advisory· Published Oct 28, 2022· Updated Jun 17, 2026
CVE-2022-3616
CVE-2022-3616
Description
Attackers can create long chains of CAs that would lead to OctoRPKI exceeding its max iterations parameter. In consequence it would cause the program to crash, preventing it from finishing the validation and leading to a denial of service. Credits to Donika Mirdita and Haya Shulman - Fraunhofer SIT, ATHENE, who discovered and reported this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/cloudflare/cfrpkiGo | < 1.4.4 | 1.4.4 |
Affected products
30+ 1 more
- (no CPE)range: 0
- cpe:2.3:a:cloudflare:octorpki:*:*:*:*:*:*:*:*range: <1.4.4
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-pmw9-567p-68pcghsaADVISORY
- github.com/cloudflare/cfrpki/security/advisories/GHSA-pmw9-567p-68pcnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-3616ghsaADVISORY
- github.com/cloudflare/cfrpki/commit/5f64bcd13477b29cd7ddff6fff3c65dfac3423caghsaWEB
News mentions
0No linked articles in our index yet.