{"id":"CVE-2025-1057","aliases":["GHSA-9jxq-5x44-gx23","PYSEC-2026-1488"],"url":"https://o3.security/vulnerability/CVE-2025-1057","summary":"Keylime: keylime registrar dos due to incompatible database entry handling","details":"### Impact\nThe Keylime `registrar` implemented more strict type checking on version 7.12.0. As a result, when updated to version 7.12.0, the `registrar` will not accept the format of the data previously stored in the database by versions  >= 7.8.0, raising an exception.\n\nThis makes the Keylime `registrar` vulnerable to a Denial-of-Service attack in an update scenario, as an attacker could populate the `registrar` database by creating multiple valid agent registrations with different UUIDs while the version is still < 7.12.0. Then, when the Keylime `registrar` is updated to the 7.12.0 version, any query to the database matching any of the entries populated by the attacker will result in failure.\n\n### Patches\nUsers should upgrade to versions >= 7.12.1\n\n### Workarounds\n- Remove the registrar database and re-register all agents\n\n### Credit\n\nReported by: Anderson Toshiyuki Sasaki/@ansasaki\nPatched by: Anderson Toshiyuki Sasaki/@ansasaki","published":"2025-03-15T08:50:48.649Z","modified":"2026-08-12T03:51:41.141422761Z","cvss":{"score":4.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"keylime","fixedVersion":"7.12.1"}],"fix":{"url":"https://github.com/keylime/keylime/commit/e08b10d86c3717006774e787542c190e2ba24fc7","label":"keylime/keylime@e08b10d"},"references":[{"type":"WEB","url":"https://access.redhat.com/downloads/content/package-browser/"},{"type":"WEB","url":"https://github.com/ansasaki/keylime/tree/base64_bytes"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2025-1057"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/1xxx/CVE-2025-1057.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-1057"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2343894"},{"type":"PACKAGE","url":"https://github.com/keylime/keylime"},{"type":"PACKAGE","url":"https://github.com/keylime/rust-keylime"},{"type":"WEB","url":"https://github.com/keylime/keylime/security/advisories/GHSA-9jxq-5x44-gx23"},{"type":"WEB","url":"https://github.com/keylime/keylime/commit/e08b10d86c3717006774e787542c190e2ba24fc7"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9jxq-5x44-gx23"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/keylime/PYSEC-2026-1488.yaml"},{"type":"WEB","url":"https://pypi.org/project/keylime"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:41.141422761Z"}}