#VU126140 Input validation error in OpenBSD
Published: April 15, 2026
OpenBSD
OpenBSD
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in RPKI client within the http_parse_header() function in /cvs/src/usr.sbin/rpki-client/http.c. A remote attacker with control over a malicious RPKI server can send specially crafted packets to the client and perform a denial of service attack.