Vulnerability DatabaseGHSA-q76j-58cx-wp5v

GHSA-q76j-58cx-wp5v
Java vulnerability analysis and mitigation

Overview

A high-severity vulnerability was discovered in RIPE NCC RPKI Validator 3.x through version 3.1-2020.07.06.14.28. The vulnerability affects the RPKI manifest validation process when objects on the manifest are hidden or expired objects are replayed. This security issue was published on November 3, 2020, and primarily impacts the RPKI (Resource Public Key Infrastructure) validation system (GitHub Advisory).

Technical details

The vulnerability is tracked as GHSA-q76j-58cx-wp5v and has been assigned a CVSS 3.1 Base Score of 7.4 (HIGH) with the vector string CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H. The issue is related to improper certificate validation (CWE-295) and involves the validation methods specified in RFC 6486bis (NVD).

Impact

When successfully exploited, this vulnerability could prevent new ROAs (Route Origin Authorisations) from being received or allow selective hiding of ROAs, causing routes to become INVALID. This could potentially lead to significant disruptions in routing systems and bypass of intended access restrictions (GitHub Advisory).

Exploitability

To exploit this vulnerability, an attacker would need to perform a man-in-the-middle attack either on the TLS connection between the validator and an RRDP repository or against a rsync-only repository (GitHub Advisory).

Mitigation and workarounds

The vulnerability was patched in version 3.2-2020.10.28.23.06. The update addresses the vulnerability by implementing validation methods from RFC 6486bis and enabling strict validation by default (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-58400CRITICAL9.1
  • Java logoJava
  • org.geonetwork-opensource:gs-web-app
NoYesSep 03, 2026
CVE-2026-63219HIGH8.6
  • Java logoJava
  • org.geonetwork-opensource:gn-services
NoYesSep 03, 2026
CVE-2026-49832HIGH8
  • Java logoJava
  • org.dspace:dspace-api
NoYesSep 02, 2026
CVE-2026-49833MEDIUM5.5
  • Java logoJava
  • org.dspace:dspace-api
NoYesSep 02, 2026
CVE-2026-49831MEDIUM5.5
  • Java logoJava
  • org.dspace:dspace-api
NoYesSep 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management