Back to Database
Status published
Medium
CVE-2021-3908
Infinite certificate chain depth results in OctoRPKI running forever
Vulnerability Description
OctoRPKI does not limit the depth of a certificate chain, allowing for a CA to create children in an ad-hoc fashion, thereby making tree traversal never end.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-3908
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Koen van Hove
References
More from Cloudflare
View All →CVE-2025-7054
Infinite loop triggered by connection ID retirement
High
8.7
CVE-2025-4821
Incorrect congestion window growth by invalid ACK ranges
High
7.5
CVE-2025-4820
Incorrect congestion window growth by optimistic ACK
Medium
5.3
CVE-2025-13353
gokey allows secret recovery from a seed file without the master password
High
7.1
CVE-2025-0651
File symlink abuse might lead to deleting files belonging to SYSTEM user
Medium
6.1
Affected Vendor
Cloudflare
View all reports →Affected Software
octorpki
Vulnerable Versions:
unspecified
Timeline
Official Publish:
November 11th, 2021
Last Modified:
September 16th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H