← Back to CVE List

CVE-2021-3909

Published: 2021-11-11T22:15Z
Last Modified: 2024-11-21T06:22Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRPKI wait forever. Specifically, the repository that OctoRPKI sends HTTP requests to will keep the connection open for a day before a response is returned, but does keep drip feeding new bytes to keep the connection alive. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt