github.com/cloudflare/cfrpki
Activity
- Latest release
- 3y ago
- Total releases
- 20
- Cadence
- ~7 days
- Last 12 months
- 0
Reach
- Stars
- —
Details
- First release
- Oct 29, 2020
| Version | Released | |
|---|---|---|
v1.5.10
patch
|
v1.5.10
patch
Dependencies (12)
+ 4 more |
|
v1.5.9
patch
|
v1.5.9
patch
Dependencies (12)
+ 4 more |
|
v1.5.8
patch
|
v1.5.8
patch
Dependencies (12)
+ 4 more |
|
v1.5.7
patch
|
v1.5.7
patch
Dependencies (12)
+ 4 more |
|
v1.5.6
patch
|
v1.5.6
patch
Dependencies (12)
+ 4 more |
|
v1.5.5
patch
|
v1.5.5
patch
Dependencies (12)
+ 4 more |
|
v1.5.4
patch
|
v1.5.4
patch
Dependencies (12)
+ 4 more |
|
v1.5.3
patch
|
v1.5.3
patch
Dependencies (12)
+ 4 more |
|
v1.5.2
patch
|
v1.5.2
patch
Dependencies (12)
+ 4 more |
|
v1.5.1
patch
|
v1.5.1
patch
Dependencies (12)
+ 4 more |
|
v1.5.0
minor
|
v1.5.0
minor
Dependencies (12)
+ 4 more |
|
v1.4.4
patch
|
v1.4.4
patch
Dependencies (12)
+ 4 more |
|
v1.4.3
patch
2 CVEs
CVE-2022-3616
GO-2022-1089
GHSA-pmw9-567p-68pc
Aug 21, 2024
OctoRPKI crashes when max iterations is reached in github.com/cloudflare/cfrpki OctoRPKI crashes when max iterations is reached in github.com/cloudflare/cfrpki Fixed in
1.4.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-3907
GO-2022-0248
GHSA-8459-6rc9-8vf8
GHSA-cqh2-vc2f-q4fh
Jul 15, 2022
Directory traversal in manifest path extraction in github.com/cloudflare/cfrpki Manifest path extraction is vulnerable to directory traversal attacks. The ExtractPathManifest function permits file paths containing relative directory components (".."), permitting files to reference arbitrary locations on the filesystem. Fixed in
1.4.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.3
patch
Dependencies (12)
+ 4 more |
|
v1.4.2
patch
3 CVEs
CVE-2022-3616
GO-2022-1089
GHSA-pmw9-567p-68pc
Aug 21, 2024
OctoRPKI crashes when max iterations is reached in github.com/cloudflare/cfrpki OctoRPKI crashes when max iterations is reached in github.com/cloudflare/cfrpki Fixed in
1.4.4
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0496
GHSA-3jhm-87m6-x959
Aug 21, 2024
Path traversal mitigation bypass in OctoRPKI in github.com/cloudflare/cfrpki Path traversal mitigation bypass in OctoRPKI in github.com/cloudflare/cfrpki Fixed in
1.4.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-3907
GO-2022-0248
GHSA-8459-6rc9-8vf8
GHSA-cqh2-vc2f-q4fh
Jul 15, 2022
Directory traversal in manifest path extraction in github.com/cloudflare/cfrpki Manifest path extraction is vulnerable to directory traversal attacks. The ExtractPathManifest function permits file paths containing relative directory components (".."), permitting files to reference arbitrary locations on the filesystem. Fixed in
1.4.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.2
patch
Dependencies (12)
+ 4 more |
|
v1.4.1
patch
4 CVEs
CVE-2022-3616
GO-2022-1089
GHSA-pmw9-567p-68pc
Aug 21, 2024
OctoRPKI crashes when max iterations is reached in github.com/cloudflare/cfrpki OctoRPKI crashes when max iterations is reached in github.com/cloudflare/cfrpki Fixed in
1.4.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-3978
GO-2022-0580
GHSA-3pqh-p72c-fj85
Aug 21, 2024
Improper Preservation of Permissions in github.com/cloudflare/cfrpki/cmd/octorpki in github.com/cloudflare/cfrpki Improper Preservation of Permissions in github.com/cloudflare/cfrpki/cmd/octorpki in github.com/cloudflare/cfrpki Fixed in
1.4.2
Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0496
GHSA-3jhm-87m6-x959
Aug 21, 2024
Path traversal mitigation bypass in OctoRPKI in github.com/cloudflare/cfrpki Path traversal mitigation bypass in OctoRPKI in github.com/cloudflare/cfrpki Fixed in
1.4.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-3907
GO-2022-0248
GHSA-8459-6rc9-8vf8
GHSA-cqh2-vc2f-q4fh
Jul 15, 2022
Directory traversal in manifest path extraction in github.com/cloudflare/cfrpki Manifest path extraction is vulnerable to directory traversal attacks. The ExtractPathManifest function permits file paths containing relative directory components (".."), permitting files to reference arbitrary locations on the filesystem. Fixed in
1.4.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.1
patch
Dependencies (12)
+ 4 more |
|
v1.4.0
minor
4 CVEs
CVE-2022-3616
GO-2022-1089
GHSA-pmw9-567p-68pc
Aug 21, 2024
OctoRPKI crashes when max iterations is reached in github.com/cloudflare/cfrpki OctoRPKI crashes when max iterations is reached in github.com/cloudflare/cfrpki Fixed in
1.4.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-3978
GO-2022-0580
GHSA-3pqh-p72c-fj85
Aug 21, 2024
Improper Preservation of Permissions in github.com/cloudflare/cfrpki/cmd/octorpki in github.com/cloudflare/cfrpki Improper Preservation of Permissions in github.com/cloudflare/cfrpki/cmd/octorpki in github.com/cloudflare/cfrpki Fixed in
1.4.2
Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0496
GHSA-3jhm-87m6-x959
Aug 21, 2024
Path traversal mitigation bypass in OctoRPKI in github.com/cloudflare/cfrpki Path traversal mitigation bypass in OctoRPKI in github.com/cloudflare/cfrpki Fixed in
1.4.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-3907
GO-2022-0248
GHSA-8459-6rc9-8vf8
GHSA-cqh2-vc2f-q4fh
Jul 15, 2022
Directory traversal in manifest path extraction in github.com/cloudflare/cfrpki Manifest path extraction is vulnerable to directory traversal attacks. The ExtractPathManifest function permits file paths containing relative directory components (".."), permitting files to reference arbitrary locations on the filesystem. Fixed in
1.4.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.0
minor
Dependencies (12)
+ 4 more |
|
v1.3.0
minor
9 CVEs
CVE-2022-3616
GO-2022-1089
GHSA-pmw9-567p-68pc
Aug 21, 2024
OctoRPKI crashes when max iterations is reached in github.com/cloudflare/cfrpki OctoRPKI crashes when max iterations is reached in github.com/cloudflare/cfrpki Fixed in
1.4.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-3978
GO-2022-0580
GHSA-3pqh-p72c-fj85
Aug 21, 2024
Improper Preservation of Permissions in github.com/cloudflare/cfrpki/cmd/octorpki in github.com/cloudflare/cfrpki Improper Preservation of Permissions in github.com/cloudflare/cfrpki/cmd/octorpki in github.com/cloudflare/cfrpki Fixed in
1.4.2
Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0496
GHSA-3jhm-87m6-x959
Aug 21, 2024
Path traversal mitigation bypass in OctoRPKI in github.com/cloudflare/cfrpki Path traversal mitigation bypass in OctoRPKI in github.com/cloudflare/cfrpki Fixed in
1.4.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-3908
GO-2022-0249
GHSA-g5gj-9ggf-9vmq
Aug 21, 2024
Infinite certificate chain depth results in OctoRPKI running forever in github.com/cloudflare/cfrpki Infinite certificate chain depth results in OctoRPKI running forever in github.com/cloudflare/cfrpki Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-3909
GO-2022-0250
GHSA-8cvr-4rrf-f244
Aug 21, 2024
Infinite open connection causes OctoRPKI to hang forever in github.com/cloudflare/cfrpki Infinite open connection causes OctoRPKI to hang forever in github.com/cloudflare/cfrpki Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-3912
GO-2022-0253
GHSA-g9wh-3vrx-r7hg
Jul 15, 2022
Resource exhaustion via GZIP bomb in github.com/cloudflare/cfrpki The HTTPFetcher.GetXML function reads a response of unlimited size into memory, permitting resource exhaustion. Fixed in
1.4.0
Updated May 20, 2024 · Source: OSV.dev
CVE-2021-3911
GO-2022-0252
GHSA-w6ww-fmfx-2x22
Jul 15, 2022
Panic on misconfigured IP address in github.com/cloudflare/cfrpki OctoRPKI crashes when a repository returns an ROA with a IP address that contains too many bits. Fixed in
1.4.0
Updated May 20, 2024 · Source: OSV.dev
CVE-2021-3910
GO-2022-0251
GHSA-5mxh-2qfv-4g7j
Jul 15, 2022
Panic on NUL character in ROA in github.com/cloudflare/cfrpki OctoRPKI crashes when a repository returns an invalid ROA that is only an encoded NUL character (\0). Fixed in
1.4.0
Updated May 20, 2024 · Source: OSV.dev
CVE-2021-3907
GO-2022-0248
GHSA-8459-6rc9-8vf8
GHSA-cqh2-vc2f-q4fh
Jul 15, 2022
Directory traversal in manifest path extraction in github.com/cloudflare/cfrpki Manifest path extraction is vulnerable to directory traversal attacks. The ExtractPathManifest function permits file paths containing relative directory components (".."), permitting files to reference arbitrary locations on the filesystem. Fixed in
1.4.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.3.0
minor
Dependencies (12)
+ 4 more |
|
v1.2.2
patch
10 CVEs
CVE-2022-3616
GO-2022-1089
GHSA-pmw9-567p-68pc
Aug 21, 2024
OctoRPKI crashes when max iterations is reached in github.com/cloudflare/cfrpki OctoRPKI crashes when max iterations is reached in github.com/cloudflare/cfrpki Fixed in
1.4.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-3978
GO-2022-0580
GHSA-3pqh-p72c-fj85
Aug 21, 2024
Improper Preservation of Permissions in github.com/cloudflare/cfrpki/cmd/octorpki in github.com/cloudflare/cfrpki Improper Preservation of Permissions in github.com/cloudflare/cfrpki/cmd/octorpki in github.com/cloudflare/cfrpki Fixed in
1.4.2
Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0496
GHSA-3jhm-87m6-x959
Aug 21, 2024
Path traversal mitigation bypass in OctoRPKI in github.com/cloudflare/cfrpki Path traversal mitigation bypass in OctoRPKI in github.com/cloudflare/cfrpki Fixed in
1.4.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-3908
GO-2022-0249
GHSA-g5gj-9ggf-9vmq
Aug 21, 2024
Infinite certificate chain depth results in OctoRPKI running forever in github.com/cloudflare/cfrpki Infinite certificate chain depth results in OctoRPKI running forever in github.com/cloudflare/cfrpki Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-3909
GO-2022-0250
GHSA-8cvr-4rrf-f244
Aug 21, 2024
Infinite open connection causes OctoRPKI to hang forever in github.com/cloudflare/cfrpki Infinite open connection causes OctoRPKI to hang forever in github.com/cloudflare/cfrpki Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-3912
GO-2022-0253
GHSA-g9wh-3vrx-r7hg
Jul 15, 2022
Resource exhaustion via GZIP bomb in github.com/cloudflare/cfrpki The HTTPFetcher.GetXML function reads a response of unlimited size into memory, permitting resource exhaustion. Fixed in
1.4.0
Updated May 20, 2024 · Source: OSV.dev
CVE-2021-3911
GO-2022-0252
GHSA-w6ww-fmfx-2x22
Jul 15, 2022
Panic on misconfigured IP address in github.com/cloudflare/cfrpki OctoRPKI crashes when a repository returns an ROA with a IP address that contains too many bits. Fixed in
1.4.0
Updated May 20, 2024 · Source: OSV.dev
CVE-2021-3910
GO-2022-0251
GHSA-5mxh-2qfv-4g7j
Jul 15, 2022
Panic on NUL character in ROA in github.com/cloudflare/cfrpki OctoRPKI crashes when a repository returns an invalid ROA that is only an encoded NUL character (\0). Fixed in
1.4.0
Updated May 20, 2024 · Source: OSV.dev
CVE-2021-3907
GO-2022-0248
GHSA-8459-6rc9-8vf8
GHSA-cqh2-vc2f-q4fh
Jul 15, 2022
Directory traversal in manifest path extraction in github.com/cloudflare/cfrpki Manifest path extraction is vulnerable to directory traversal attacks. The ExtractPathManifest function permits file paths containing relative directory components (".."), permitting files to reference arbitrary locations on the filesystem. Fixed in
1.4.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-3761
GO-2022-0246
GHSA-c8xp-8mf3-62h9
Jul 15, 2022
Insufficient validation in github.com/cloudflare/cfrpki The ROAEntry.Validate function fails to perform bounds checks on the MaxLength field, allowing invalid values to pass validation. Fixed in
1.3.0
References Updated May 20, 2024 · Source: OSV.dev |
v1.2.2
patch
Dependencies (12)
+ 4 more |
|
v1.2.1
patch
10 CVEs
CVE-2022-3616
GO-2022-1089
GHSA-pmw9-567p-68pc
Aug 21, 2024
OctoRPKI crashes when max iterations is reached in github.com/cloudflare/cfrpki OctoRPKI crashes when max iterations is reached in github.com/cloudflare/cfrpki Fixed in
1.4.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-3978
GO-2022-0580
GHSA-3pqh-p72c-fj85
Aug 21, 2024
Improper Preservation of Permissions in github.com/cloudflare/cfrpki/cmd/octorpki in github.com/cloudflare/cfrpki Improper Preservation of Permissions in github.com/cloudflare/cfrpki/cmd/octorpki in github.com/cloudflare/cfrpki Fixed in
1.4.2
Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0496
GHSA-3jhm-87m6-x959
Aug 21, 2024
Path traversal mitigation bypass in OctoRPKI in github.com/cloudflare/cfrpki Path traversal mitigation bypass in OctoRPKI in github.com/cloudflare/cfrpki Fixed in
1.4.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-3908
GO-2022-0249
GHSA-g5gj-9ggf-9vmq
Aug 21, 2024
Infinite certificate chain depth results in OctoRPKI running forever in github.com/cloudflare/cfrpki Infinite certificate chain depth results in OctoRPKI running forever in github.com/cloudflare/cfrpki Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-3909
GO-2022-0250
GHSA-8cvr-4rrf-f244
Aug 21, 2024
Infinite open connection causes OctoRPKI to hang forever in github.com/cloudflare/cfrpki Infinite open connection causes OctoRPKI to hang forever in github.com/cloudflare/cfrpki Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-3912
GO-2022-0253
GHSA-g9wh-3vrx-r7hg
Jul 15, 2022
Resource exhaustion via GZIP bomb in github.com/cloudflare/cfrpki The HTTPFetcher.GetXML function reads a response of unlimited size into memory, permitting resource exhaustion. Fixed in
1.4.0
Updated May 20, 2024 · Source: OSV.dev
CVE-2021-3911
GO-2022-0252
GHSA-w6ww-fmfx-2x22
Jul 15, 2022
Panic on misconfigured IP address in github.com/cloudflare/cfrpki OctoRPKI crashes when a repository returns an ROA with a IP address that contains too many bits. Fixed in
1.4.0
Updated May 20, 2024 · Source: OSV.dev
CVE-2021-3910
GO-2022-0251
GHSA-5mxh-2qfv-4g7j
Jul 15, 2022
Panic on NUL character in ROA in github.com/cloudflare/cfrpki OctoRPKI crashes when a repository returns an invalid ROA that is only an encoded NUL character (\0). Fixed in
1.4.0
Updated May 20, 2024 · Source: OSV.dev
CVE-2021-3907
GO-2022-0248
GHSA-8459-6rc9-8vf8
GHSA-cqh2-vc2f-q4fh
Jul 15, 2022
Directory traversal in manifest path extraction in github.com/cloudflare/cfrpki Manifest path extraction is vulnerable to directory traversal attacks. The ExtractPathManifest function permits file paths containing relative directory components (".."), permitting files to reference arbitrary locations on the filesystem. Fixed in
1.4.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-3761
GO-2022-0246
GHSA-c8xp-8mf3-62h9
Jul 15, 2022
Insufficient validation in github.com/cloudflare/cfrpki The ROAEntry.Validate function fails to perform bounds checks on the MaxLength field, allowing invalid values to pass validation. Fixed in
1.3.0
References Updated May 20, 2024 · Source: OSV.dev |
v1.2.1
patch
Dependencies (12)
+ 4 more |
|
v1.2.0
initial
10 CVEs
CVE-2022-3616
GO-2022-1089
GHSA-pmw9-567p-68pc
Aug 21, 2024
OctoRPKI crashes when max iterations is reached in github.com/cloudflare/cfrpki OctoRPKI crashes when max iterations is reached in github.com/cloudflare/cfrpki Fixed in
1.4.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-3978
GO-2022-0580
GHSA-3pqh-p72c-fj85
Aug 21, 2024
Improper Preservation of Permissions in github.com/cloudflare/cfrpki/cmd/octorpki in github.com/cloudflare/cfrpki Improper Preservation of Permissions in github.com/cloudflare/cfrpki/cmd/octorpki in github.com/cloudflare/cfrpki Fixed in
1.4.2
Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0496
GHSA-3jhm-87m6-x959
Aug 21, 2024
Path traversal mitigation bypass in OctoRPKI in github.com/cloudflare/cfrpki Path traversal mitigation bypass in OctoRPKI in github.com/cloudflare/cfrpki Fixed in
1.4.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-3908
GO-2022-0249
GHSA-g5gj-9ggf-9vmq
Aug 21, 2024
Infinite certificate chain depth results in OctoRPKI running forever in github.com/cloudflare/cfrpki Infinite certificate chain depth results in OctoRPKI running forever in github.com/cloudflare/cfrpki Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-3909
GO-2022-0250
GHSA-8cvr-4rrf-f244
Aug 21, 2024
Infinite open connection causes OctoRPKI to hang forever in github.com/cloudflare/cfrpki Infinite open connection causes OctoRPKI to hang forever in github.com/cloudflare/cfrpki Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-3912
GO-2022-0253
GHSA-g9wh-3vrx-r7hg
Jul 15, 2022
Resource exhaustion via GZIP bomb in github.com/cloudflare/cfrpki The HTTPFetcher.GetXML function reads a response of unlimited size into memory, permitting resource exhaustion. Fixed in
1.4.0
Updated May 20, 2024 · Source: OSV.dev
CVE-2021-3911
GO-2022-0252
GHSA-w6ww-fmfx-2x22
Jul 15, 2022
Panic on misconfigured IP address in github.com/cloudflare/cfrpki OctoRPKI crashes when a repository returns an ROA with a IP address that contains too many bits. Fixed in
1.4.0
Updated May 20, 2024 · Source: OSV.dev
CVE-2021-3910
GO-2022-0251
GHSA-5mxh-2qfv-4g7j
Jul 15, 2022
Panic on NUL character in ROA in github.com/cloudflare/cfrpki OctoRPKI crashes when a repository returns an invalid ROA that is only an encoded NUL character (\0). Fixed in
1.4.0
Updated May 20, 2024 · Source: OSV.dev
CVE-2021-3907
GO-2022-0248
GHSA-8459-6rc9-8vf8
GHSA-cqh2-vc2f-q4fh
Jul 15, 2022
Directory traversal in manifest path extraction in github.com/cloudflare/cfrpki Manifest path extraction is vulnerable to directory traversal attacks. The ExtractPathManifest function permits file paths containing relative directory components (".."), permitting files to reference arbitrary locations on the filesystem. Fixed in
1.4.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-3761
GO-2022-0246
GHSA-c8xp-8mf3-62h9
Jul 15, 2022
Insufficient validation in github.com/cloudflare/cfrpki The ROAEntry.Validate function fails to perform bounds checks on the MaxLength field, allowing invalid values to pass validation. Fixed in
1.3.0
References Updated May 20, 2024 · Source: OSV.dev |
v1.2.0
initial
Dependencies (12)
+ 4 more |