{"id":"CVE-2025-66564","aliases":["GHSA-4qg8-fj49-pxjh","GO-2025-4192"],"title":"Sigstore Timestamp Authority allocates excessive memory during request parsing","summary":"Sigstore Timestamp Authority allocates excessive memory during request parsing","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","vendor":"sigstore","product":"github.com/sigstore/timestamp-authority","ecosystem":"go","affected":["github.com/sigstore/timestamp-authority < 2.0.3"],"patched":["github.com/sigstore/timestamp-authority 2.0.3"],"published":"2025-12-05","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:31.413997158Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-4qg8-fj49-pxjh","references":[{"url":"https://github.com/sigstore/timestamp-authority/security/advisories/GHSA-4qg8-fj49-pxjh"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66564"},{"url":"https://github.com/sigstore/timestamp-authority/commit/0cae34e197d685a14904e0bad135b89d13b69421"},{"url":"https://github.com/sigstore/timestamp-authority"}],"tags":["osv","go"],"epss":0.00443,"epssPercentile":0.37907,"ingestedAt":"2026-09-12T03:13:01.753Z","slug":"CVE-2025-66564","body":"## Overview\n\n### Impact\n\n**Excessive memory allocation**\n\nFunction [api.ParseJSONRequest](https://github.com/sigstore/timestamp-authority/blob/26d7d426d3000abdbdf2df34de56bb92246c0365/pkg/api/timestamp.go#L63) currently splits (via a call to [strings.Split](https://pkg.go.dev/strings#Split)) an optionally-provided OID (which is untrusted data) on periods. Similarly, function [api.getContentType](https://github.com/sigstore/timestamp-authority/blob/26d7d426d3000abdbdf2df34de56bb92246c0365/pkg/api/timestamp.go#L114) splits the `Content-Type` header (which is also untrusted data) on an `application` string.\n\nAs a result, in the face of a malicious request with either an excessively long OID in the payload containing many period characters or a malformed `Content-Type` header, a call to `api.ParseJSONRequest` or `api.getContentType` incurs allocations of O(n) bytes (where n stands for the length of the function's argument). Relevant weakness: [CWE-405: Asymmetric Resource Consumption (Amplification)](https://cwe.mitre.org/data/definitions/405.html)\n\n### Patches\n\nUpgrade to v2.0.3.\n\n### Workarounds\n\nThere are no workarounds with the service itself. If the service is behind a load balancer, configure the load balancer to reject excessively large requests.\n\n## Affected packages\n\n- `github.com/sigstore/timestamp-authority < 2.0.3`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/sigstore/timestamp-authority 2.0.3`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}