CVE-2021-43174
Rust vulnerability analysis and mitigation

Overview

CVE-2021-43174 affects NLnet Labs Routinator versions 0.9.0 through 0.10.1. The vulnerability was discovered in November 2021 and involves the software's support for gzip transfer encoding when querying RRDP (Repository Delta Protocol) repositories (NVD, Vendor Advisory).

Technical details

The vulnerability stems from the software's handling of XML data in RRDP repositories. When processing gzip-encoded XML data, the compression scheme can effectively compress large amounts of whitespace, resulting in small compressed files that expand dramatically during decompression. This can lead to an out-of-memory condition in Routinator when parsing input data while waiting for the next XML element. The vulnerability has been assigned a CVSS v3.1 Base Score of 7.5 (HIGH) with a vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (NVD).

Impact

When exploited, this vulnerability can cause Routinator to crash due to out-of-memory conditions when processing maliciously crafted RRDP repository data. This can lead to service disruption and affect the availability of the RPKI validation service (Vendor Advisory).

Mitigation and workarounds

The issue has been addressed in Routinator version 0.10.2 by completely disabling gzip encoding. Users are advised to upgrade to version 0.10.2 or later to resolve this vulnerability. The vendor decided to disable gzip encoding completely rather than just fixing the out-of-memory condition, as the processing of large amounts of decompressed data would still lead to severe delays in validation runs (Vendor Advisory).

Additional resources


SourceThis report was generated using AI

Related Rust vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-65807HIGH8.4
  • RustRust
  • sd
NoNoDec 10, 2025
CVE-2025-66627HIGH7.8
  • RustRust
  • wasmi
NoYesDec 09, 2025
CVE-2025-67487MEDIUM5.5
  • RustRust
  • static-web-server
NoYesDec 09, 2025
CVE-2025-66622LOW1.3
  • RustRust
  • matrix-sdk-base
NoYesDec 09, 2025
RUSTSEC-2025-0135N/AN/A
  • RustRust
  • matrix-sdk-base
NoYesDec 08, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management