Skip to main content

Asymmetric Resource Consumption (Amplification)

CVE-2025-66564

Severity High
Score 7.5/10

Summary

Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. In versions prior to 2.0.3, Function "api.ParseJSONRequest()" currently splits (via a call to "strings.Split") an optionally-provided OID (which is untrusted data) on periods. Similarly, function "api.getContentType()" splits the Content-Type header (which is also untrusted data) on an application string. As a result, in the face of a malicious request with either an excessively long OID in the payload containing many period characters or a malformed Content-Type header, a call to "api.ParseJSONRequest()" or "api.getContentType()" incurs allocations of O(n) bytes (where n stands for the length of the function's argument). This vulnerability is fixed in 2.0.3.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • NONE
  • HIGH

CWE-405 - Asymmetric Resource Consumption (Amplification)

Software that does not appropriately monitor or control resource consumption can lead to adverse system performance.

Advisory Timeline

  • Published