CVE-2022-3616 - CVE House
Back to Database
Status published Medium CVE-2022-3616

OctoRPKI crash when maximum iterations number is reached

Vulnerability Description

Attackers can create long chains of CAs that would lead to OctoRPKI exceeding its max iterations parameter. In consequence it would cause the program to crash, preventing it from finishing the validation and leading to a denial of service. Credits to Donika Mirdita and Haya Shulman - Fraunhofer SIT, ATHENE, who discovered and reported this vulnerability.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-3616

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Donika Mirdita - Fraunhofer SIT, ATHENE
  • Haya Shulman - Fraunhofer SIT, ATHENE

Affected Vendor

Affected Software

OctoRPKI
Vulnerable Versions:
0

Timeline

Official Publish: October 28th, 2022
Last Modified: May 5th, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:H

Weaknesses (CWE)