[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2023-29409":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T08:55:32.481Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":86,"aliases":87,"duplicate_of":9,"upstream":90,"downstream":91,"duplicates":160,"related":161,"reserved_at":9,"published_at":204,"modified_at":205,"state":206,"summary":207,"references_raw":216,"kevs":250,"epss":251,"epss_history":254,"metrics":523,"affected":529},"CVE-2023-29409","Extremely large RSA keys in certificate chains can cause a client/server to expend significant CPU time verifying signatures. With fix, the size of RSA keys transmitted during handshakes is restricted to \u003C= 8192 bits. Based on a survey of publicly trusted RSA keys, there are currently only three certificates in circulation with keys larger than this, and all three appear to be test certificates that are not actively deployed. It is possible there are larger keys in use in private PKIs, but we target the web PKI, so causing breakage here in the interests of increasing the default safety of users of crypto/tls seems reasonable.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-400","Uncontrolled Resource Consumption","The product does not properly control the allocation and maintenance of a limited resource.","weakness","Draft","Class","High",[20,24,82],{"id":21,"name":22,"techniques":23},"CAPEC-147","XML Ping of the Death",[],{"id":25,"name":26,"techniques":27},"CAPEC-227","Sustained Client Engagement",[28],{"id":29,"name":30,"tactics":31,"countermeasures":35},"T1499","Endpoint Denial of Service",[32],{"id":33,"name":34},"TA0105","Impact",[36,41,45,49,53,57,61,65,69,73,78],{"id":37,"name":38,"tactic":39},"D3-UGLPA","User Geolocation Logon Pattern Analysis",{"name":40},"Detect",{"id":42,"name":43,"tactic":44},"D3-PMAD","Protocol Metadata Anomaly Detection",{"name":40},{"id":46,"name":47,"tactic":48},"D3-CSPP","Client-server Payload Profiling",{"name":40},{"id":50,"name":51,"tactic":52},"D3-PHDURA","Per Host Download-Upload Ratio Analysis",{"name":40},{"id":54,"name":55,"tactic":56},"D3-NTSA","Network Traffic Signature Analysis",{"name":40},{"id":58,"name":59,"tactic":60},"D3-APCA","Application Protocol Command Analysis",{"name":40},{"id":62,"name":63,"tactic":64},"D3-NTCD","Network Traffic Community Deviation",{"name":40},{"id":66,"name":67,"tactic":68},"D3-RTSD","Remote Terminal Session Detection",{"name":40},{"id":70,"name":71,"tactic":72},"D3-ISVA","Inbound Session Volume Analysis",{"name":40},{"id":74,"name":75,"tactic":76},"D3-NTF","Network Traffic Filtering",{"name":77},"Isolate",{"id":79,"name":80,"tactic":81},"D3-ITF","Inbound Traffic Filtering",{"name":77},{"id":83,"name":84,"techniques":85},"CAPEC-492","Regular Expression Exponential Blowup",[],[],[88,89],"GO-2023-1987","BIT-golang-2023-29409",[],[92,94,96,98,100,102,104,106,108,110,112,114,116,118,120,122,124,126,128,130,132,134,136,138,140,142,144,146,148,150,152,154,156,158],{"_key":93},"UBUNTU-CVE-2023-29409",{"_key":95},"SUSE-SU-2023:3840-1",{"_key":97},"SUSE-SU-2023:3841-1",{"_key":99},"SUSE-SU-2023:3474-1",{"_key":101},"SUSE-SU-2023:3861-1",{"_key":103},"SUSE-SU-2023:3867-1",{"_key":105},"SUSE-SU-2023:3875-1",{"_key":107},"SUSE-SU-2023:3885-1",{"_key":109},"SUSE-SU-2023:3181-1",{"_key":111},"SUSE-SU-2023:3263-1",{"_key":113},"SUSE-SU-2023:3868-1",{"_key":115},"SUSE-SU-2023:3886-1",{"_key":117},"SUSE-SU-2023:3888-1",{"_key":119},"OPENSUSE-SU-2024:13093-1",{"_key":121},"OPENSUSE-SU-2024:13094-1",{"_key":123},"DEBIAN-CVE-2023-29409",{"_key":125},"RHSA-2023:7762",{"_key":127},"RHSA-2023:7763",{"_key":129},"RHSA-2023:7764",{"_key":131},"RHSA-2023:7765",{"_key":133},"RHSA-2023:7766",{"_key":135},"RHSA-2024:0121",{"_key":137},"RHSA-2024:0292",{"_key":139},"RHSA-2024:0293",{"_key":141},"RHSA-2024:2988",{"_key":143},"RHSA-2023:5009",{"_key":145},"RHSA-2023:5721",{"_key":147},"RHSA-2023:5738",{"_key":149},"RHSA-2023:5805",{"_key":151},"RHSA-2023:5964",{"_key":153},"RHSA-2023:5965",{"_key":155},"RHSA-2023:5969",{"_key":157},"RHSA-2023:6298",{"_key":159},"RHSA-2023:6840",[],[162,163,164,165,166,167,168,169,170,171,172,173,174,175,176,177,178,179,180,181,182,183,184,185,186,187,188,189,190,191,192,193,194,196,198,200,202],{"_key":95},{"_key":97},{"_key":99},{"_key":101},{"_key":103},{"_key":105},{"_key":107},{"_key":143},{"_key":145},{"_key":147},{"_key":149},{"_key":151},{"_key":153},{"_key":155},{"_key":157},{"_key":159},{"_key":125},{"_key":127},{"_key":129},{"_key":131},{"_key":133},{"_key":135},{"_key":137},{"_key":139},{"_key":141},{"_key":109},{"_key":111},{"_key":113},{"_key":115},{"_key":117},{"_key":119},{"_key":121},{"_key":195},"CGA-CGW7-RJ35-5W6F",{"_key":197},"CGA-CMWR-WX85-RX2V",{"_key":199},"CGA-Q562-PM5J-7GR3",{"_key":201},"CGA-W6RR-MR3C-2234",{"_key":203},"CGA-RVHW-45GQ-QM8Q","2023-08-02T19:47:23.829Z","2025-02-13T16:49:16.368Z","Modified",{"cisa_kev":208,"cisa_ransomware":208,"cisa_vendor":9,"epss_severity":209,"epss_score":210,"severity":211,"severity_score":212,"severity_version":213,"severity_source":214,"severity_vector":215,"severity_status":206},false,"low",0.00122,"medium",5.3,"v3.1","nvd","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",[217,227,232,238,242,246],{"url":218,"sources":219,"tags":222},"https://go.dev/issue/61460",[220,214,221],"cve.org","osv_go",[223,224,225,226],"Issue Tracking","Patch","Vendor Advisory","REPORT",{"url":228,"sources":229,"tags":230},"https://go.dev/cl/515257",[220,214,221],[224,231],"FIX",{"url":233,"sources":234,"tags":235},"https://groups.google.com/g/golang-announce/c/X0b6CsSAaYI/m/Efv5DbZ9AwAJ",[220,214,221],[236,225,237],"Mailing List","WEB",{"url":239,"sources":240,"tags":241},"https://pkg.go.dev/vuln/GO-2023-1987",[220,214],[224,225],{"url":243,"sources":244,"tags":245},"https://security.netapp.com/advisory/ntap-20230831-0010/",[220,214],[],{"url":247,"sources":248,"tags":249},"https://security.gentoo.org/glsa/202311-09",[220,214],[],[],{"date":252,"score":210,"percentile":253},"2026-06-04",0.3086,[255,259,262,265,268,271,274,277,280,283,286,289,292,295,298,302,305,308,311,313,316,319,322,325,328,331,334,337,340,342,345,348,351,353,356,359,362,365,368,371,374,377,380,383,386,389,392,395,398,401,404,407,410,413,416,419,422,424,427,430,433,436,439,442,445,448,450,453,456,460,463,466,469,472,475,478,481,484,487,490,493,496,499,502,505,508,511,514,517,520],{"date":256,"score":257,"percentile":258},"2025-11-04",0.00112,0.3036,{"date":260,"score":257,"percentile":261},"2025-11-05",0.30336,{"date":263,"score":257,"percentile":264},"2025-11-06",0.30348,{"date":266,"score":257,"percentile":267},"2025-11-07",0.30355,{"date":269,"score":257,"percentile":270},"2025-11-08",0.30356,{"date":272,"score":257,"percentile":273},"2025-11-09",0.30334,{"date":275,"score":257,"percentile":276},"2025-11-10",0.30291,{"date":278,"score":257,"percentile":279},"2025-11-11",0.30309,{"date":281,"score":257,"percentile":282},"2025-11-12",0.30353,{"date":284,"score":257,"percentile":285},"2025-11-13",0.3037,{"date":287,"score":257,"percentile":288},"2025-11-14",0.30366,{"date":290,"score":257,"percentile":291},"2025-11-15",0.30359,{"date":293,"score":257,"percentile":294},"2025-11-16",0.30331,{"date":296,"score":257,"percentile":297},"2025-11-17",0.30314,{"date":299,"score":300,"percentile":301},"2025-11-18",0.01987,0.82146,{"date":303,"score":300,"percentile":304},"2025-11-19",0.82147,{"date":306,"score":300,"percentile":307},"2025-11-20",0.82152,{"date":309,"score":257,"percentile":310},"2025-11-21",0.30352,{"date":312,"score":257,"percentile":291},"2025-11-22",{"date":314,"score":257,"percentile":315},"2025-11-23",0.30327,{"date":317,"score":257,"percentile":318},"2025-11-24",0.30304,{"date":320,"score":257,"percentile":321},"2025-11-25",0.30298,{"date":323,"score":257,"percentile":324},"2025-11-26",0.30296,{"date":326,"score":257,"percentile":327},"2025-11-27",0.30308,{"date":329,"score":257,"percentile":330},"2025-11-28",0.30286,{"date":332,"score":257,"percentile":333},"2025-11-29",0.30275,{"date":335,"score":257,"percentile":336},"2025-11-30",0.30252,{"date":338,"score":257,"percentile":339},"2025-12-01",0.30328,{"date":341,"score":257,"percentile":258},"2025-12-02",{"date":343,"score":257,"percentile":344},"2025-12-03",0.30363,{"date":346,"score":257,"percentile":347},"2025-12-04",0.30267,{"date":349,"score":257,"percentile":350},"2025-12-05",0.30306,{"date":352,"score":257,"percentile":318},"2025-12-06",{"date":354,"score":257,"percentile":355},"2025-12-07",0.30281,{"date":357,"score":257,"percentile":358},"2025-12-08",0.30288,{"date":360,"score":257,"percentile":361},"2025-12-09",0.30346,{"date":363,"score":257,"percentile":364},"2025-12-10",0.30408,{"date":366,"score":257,"percentile":367},"2025-12-11",0.30437,{"date":369,"score":257,"percentile":370},"2025-12-12",0.30469,{"date":372,"score":257,"percentile":373},"2025-12-13",0.30458,{"date":375,"score":257,"percentile":376},"2025-12-14",0.30433,{"date":378,"score":257,"percentile":379},"2025-12-15",0.30402,{"date":381,"score":257,"percentile":382},"2025-12-16",0.30421,{"date":384,"score":257,"percentile":385},"2025-12-17",0.30462,{"date":387,"score":257,"percentile":388},"2025-12-18",0.30511,{"date":390,"score":257,"percentile":391},"2025-12-19",0.30523,{"date":393,"score":257,"percentile":394},"2025-12-20",0.305,{"date":396,"score":257,"percentile":397},"2025-12-21",0.30453,{"date":399,"score":257,"percentile":400},"2025-12-22",0.30413,{"date":402,"score":257,"percentile":403},"2025-12-23",0.30388,{"date":405,"score":257,"percentile":406},"2025-12-24",0.30393,{"date":408,"score":257,"percentile":409},"2025-12-25",0.30465,{"date":411,"score":257,"percentile":412},"2025-12-26",0.30463,{"date":414,"score":257,"percentile":415},"2025-12-27",0.30467,{"date":417,"score":257,"percentile":418},"2025-12-28",0.3039,{"date":420,"score":257,"percentile":421},"2025-12-29",0.30364,{"date":423,"score":257,"percentile":258},"2025-12-30",{"date":425,"score":257,"percentile":426},"2025-12-31",0.30409,{"date":428,"score":257,"percentile":429},"2026-01-01",0.30536,{"date":431,"score":257,"percentile":432},"2026-01-02",0.30527,{"date":434,"score":257,"percentile":435},"2026-01-03",0.30504,{"date":437,"score":257,"percentile":438},"2026-01-04",0.30376,{"date":440,"score":257,"percentile":441},"2026-01-05",0.30369,{"date":443,"score":257,"percentile":444},"2026-01-06",0.30379,{"date":446,"score":257,"percentile":447},"2026-01-07",0.3041,{"date":449,"score":257,"percentile":367},"2026-01-08",{"date":451,"score":257,"percentile":452},"2026-01-09",0.30431,{"date":454,"score":257,"percentile":455},"2026-01-10",0.30427,{"date":457,"score":458,"percentile":459},"2026-01-11",0.00125,0.3257,{"date":461,"score":458,"percentile":462},"2026-01-12",0.32497,{"date":464,"score":458,"percentile":465},"2026-01-13",0.3248,{"date":467,"score":458,"percentile":468},"2026-01-14",0.32527,{"date":470,"score":458,"percentile":471},"2026-01-15",0.32523,{"date":473,"score":458,"percentile":474},"2026-01-16",0.32545,{"date":476,"score":458,"percentile":477},"2026-01-17",0.32535,{"date":479,"score":458,"percentile":480},"2026-01-18",0.32476,{"date":482,"score":458,"percentile":483},"2026-01-19",0.32444,{"date":485,"score":458,"percentile":486},"2026-01-20",0.32424,{"date":488,"score":458,"percentile":489},"2026-01-21",0.32383,{"date":491,"score":458,"percentile":492},"2026-01-22",0.32353,{"date":494,"score":458,"percentile":495},"2026-01-23",0.32417,{"date":497,"score":458,"percentile":498},"2026-01-24",0.32426,{"date":500,"score":458,"percentile":501},"2026-01-25",0.32356,{"date":503,"score":458,"percentile":504},"2026-01-26",0.32265,{"date":506,"score":458,"percentile":507},"2026-01-27",0.32251,{"date":509,"score":458,"percentile":510},"2026-01-28",0.32225,{"date":512,"score":458,"percentile":513},"2026-01-29",0.32186,{"date":515,"score":458,"percentile":516},"2026-01-30",0.32178,{"date":518,"score":458,"percentile":519},"2026-01-31",0.32185,{"date":521,"score":458,"percentile":522},"2026-02-01",0.32277,[524],{"source":214,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":525,"cvss_v4_0":9},{"baseScore":212,"baseSeverity":526,"vectorString":215,"impactScore":527,"exploitabilityScore":528},"MEDIUM",2.3,10,[530,549,565],{"ecosystem":9,"name":531,"vendor":532,"product":531,"cpe_part":533,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":534},"crypto/tls","go standard library","a",[535,540,545],{"version":536,"is_range":537,"range_type":220,"version_start":9,"version_start_type":9,"version_end":538,"version_end_type":539,"fixed_in":9},"\u003C 1.19.12",true,"1.19.12","excluding",{"version":541,"is_range":537,"range_type":220,"version_start":542,"version_start_type":543,"version_end":544,"version_end_type":539,"fixed_in":9},">= 1.20.0-0, \u003C 1.20.7","1.20.0-0","including","1.20.7",{"version":546,"is_range":537,"range_type":220,"version_start":547,"version_start_type":543,"version_end":548,"version_end_type":539,"fixed_in":9},">= 1.21.0-0, \u003C 1.21.0-rc.4","1.21.0-0","1.21.0-rc.4",{"ecosystem":9,"name":550,"vendor":551,"product":550,"cpe_part":533,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":552},"go","golang",[553,556,559,561,563],{"version":554,"is_range":537,"range_type":555,"version_start":9,"version_start_type":9,"version_end":538,"version_end_type":539,"fixed_in":9},"lt1.19.12","cpe",{"version":557,"is_range":537,"range_type":555,"version_start":558,"version_start_type":543,"version_end":544,"version_end_type":539,"fixed_in":9},"gte1.20.0_lt1.20.7","1.20.0",{"version":560,"is_range":208,"range_type":555,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"1.21.0:rc1",{"version":562,"is_range":208,"range_type":555,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"1.21.0:rc2",{"version":564,"is_range":208,"range_type":555,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"1.21.0:rc3",{"ecosystem":566,"name":567,"vendor":566,"product":567,"cpe_part":9,"purl_type":551,"purl_namespace":9,"purl_name":567,"source":9,"versions":568},"Go","stdlib",[569],{"version":570,"is_range":537,"range_type":571,"version_start":547,"version_start_type":543,"version_end":548,"version_end_type":539,"fixed_in":9},"gte1_21_0_0_lt1_21_0_rc_4","semver"]