CVE-2025-66564
Last modified
CVE-2025-66564 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.0.3, Function api.ParseJSONRequest currently splits (via a call to strings.Split) an optionally-provided OID (which is untrusted data) on periods. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.0.3, Function api.ParseJSONRequest currently splits (via a call to strings.Split) an optionally-provided OID (which is untrusted data) on periods. Similarly, function api.getContentType splits the Content-Type header (which is also untrusted data) on an application string. As a result, in the face of a malicious request with either an excessively long OID in the payload containing many period characters or a malformed Content-Type header, a call to api.ParseJSONRequest or api.getContentType incurs allocations of O(n) bytes (where n stands for the length of the function's argument). This vulnerability is fixed in 2.0.3.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linuxfoundation | Sigstore Timestamp Authority | < 2.0.3 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-66564?
How severe is CVE-2025-66564?
How do I fix CVE-2025-66564?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-66559Taiko Alethia is an Ethereum-equivalent, permissionless, bas…8
- CVE-2025-6656PDF-XChange Editor PRC File Parsing Out-Of-Bounds Read Infor…3.3
- CVE-2025-66560Quarkus is a Cloud Native, (Linux) Container First framework…7.5
- CVE-2025-66561SysReptor is a fully customizable pentest reporting platform…5.4
- CVE-2025-66562TUUI is a desktop MCP client designed as a tool unitary util…9.6
- CVE-2025-66563Monkeytype is a minimalistic and customizable typing test. I…6.1
- CVE-2025-66565Fiber Utils is a collection of common functions created for …9.8
- CVE-2025-66566yawkat LZ4 Java provides LZ4 compression for Java. Insuffici…8.2
- CVE-2025-66567The ruby-saml library is for implementing the client side of…9.1
- CVE-2025-66568The ruby-saml library implements the client side of an SAML …9.1
- CVE-2025-6657PDF-XChange Editor PRC File Parsing Out-Of-Bounds Read Infor…3.3
- CVE-2025-66570cpp-httplib is a C++11 single-file header-only cross platfor…9.8
Are you affected by CVE-2025-66564?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
