Executive brief
Picotls is a cryptographic TLS library that includes its own ASN.1 parser for handling private keys in PKCS#8 format. A flaw in the parser's recursion handling allows an attacker to craft a maliciously nested certificate or key file that, when loaded by an application, causes a stack overflow and crashes the process. This affects applications using picotls's minicrypto backend to parse untrusted key files.
Technical details
The vulnerability is a stack exhaustion flaw in picotls's custom ASN.1 validation helper used by the minicrypto cryptographic backend. The validator recursively descends into constructed ASN.1 elements without enforcing a maximum nesting depth, allowing a deeply nested DER-encoded structure to exhaust the call stack. An attacker can exploit this via ptls_minicrypto_load_private_key() or the public ASN.1 validation API when parsing untrusted DER-encoded data. The impact is denial of service through application crash. The OpenSSL (libcrypto) backend is unaffected as it does not use picotls's custom ASN.1 validator. The fix adds depth limiting to ASN.1 recursion.
Affected products
- h2o picotls commits prior to c14231d
Timeline
- 2026-05-29: disclosed: GitHub Security Advisory GHSA-84f5-m5x2-82q4 published
- 2026-05-29: patched: Fix merged in commit c14231d
- 2026-08-21: advisory: CVE-2026-45271 published