picotls has infinite recursion in the minicrypto ASN.1 decoder
Published Aug 21, 2026
5.5
MEDIUMCVSS 3.1
EPSS 0.15%
Description
Picotls is a TLS protocol library that allows users select different crypto backends based on their use case. Picotls implements its own ASN.1 validation helper, which is used by the minicrypto backend while parsing local PKCS#8 private keys. Prior to commit c14231d801407640bc42c2dcf92783409ea6a7c7, the validator recursively descends into constructed ASN.1 elements without enforcing a maximum nesting depth. If an application loads an attacker-supplied private-key file through ptls_minicrypto_load_private_key(), or otherwise calls the public ASN.1 validation API on untrusted DER, a crafted deeply nested ASN.1 structure can exhaust the process stack and crash the application. Note that the libcrypto (OpenSSL) backend does not use the ASN.1 validation helper of picotls, and therefore is immune to this vulnerability. The vulnerability has been addressed in commit c14231d801407640bc42c2dcf92783409ea6a7c7.
Affected products
-
- Version < c14231d801407640bc42c2dcf92783409ea6a7c7StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Aug 25, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
Jun–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 0.15% (0.00151) | 3.63th | v5 (v2026.06.15) |
| Aug 22, 2026 | 0.11% (0.00113) | 1.66th | v5 (v2026.06.15) |
| Jun 12, 2026 | 0.01% (0.00014) | 2.73th | v4 (v2025.03.14) |
References (2)
- https://github.com/h2o/picotls/commit/c14231d801407640bc42c2dcf92783409ea6a7c7 x_refsource_MISC
- https://github.com/h2o/picotls/security/advisories/GHSA-84f5-m5x2-82q4 x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://github.com/h2o/picotls/commit/c14231d801407640bc42c2dcf92783409ea6a7c7 | x_refsource_MISC | |
| https://github.com/h2o/picotls/security/advisories/GHSA-84f5-m5x2-82q4 | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.