{"id":"CVE-2024-56169","details":"A validation integrity issue was discovered in Fort through 1.6.4 before 2.0.0. RPKI Relying Parties (such as Fort) are supposed to maintain a backup cache of the remote RPKI data. This can be employed as a fallback in case a new fetch fails or yields incorrect files. However, the product currently uses its cache merely as a bandwidth saving tool (because fetching is performed through deltas). If a fetch fails midway or yields incorrect files, there is no viable fallback. This leads to incomplete route origin validation data.","modified":"2026-08-12T15:15:45.562080Z","published":"2024-12-18T00:00:00Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"fixed":"2.0.0"}],"source":"DESCRIPTION"}],"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/56xxx/CVE-2024-56169.json"},"references":[{"type":"WEB","url":"https://nicmx.github.io/FORT-validator/CVE.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/56xxx/CVE-2024-56169.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-56169"},{"type":"REPORT","url":"https://github.com/NICMx/FORT-validator/issues/82"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nicmx/fort-validator","events":[{"introduced":"0"},{"fixed":"b0914e8cf864dabc99db81d247054e063c71e003"}],"database_specific":{"cpe":"cpe:2.3:a:nicmx:fort_validator:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.6.4"},{"last_affected":"1.6.6"}],"source":["DESCRIPTION","CPE_RANGE"]}}],"versions":["1.6.3","1.6.2","1.6.1","1.6.0","1.5.4","1.5.3","v1.5.1","v1.5.0","v1.4.0","v1.3.0","v1.2.1","v1.2.0","v1.1.1","v1.1.0","v1.0.0","v0.0.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-56169.json","vanir_signatures_modified":"2026-08-12T15:15:45Z","vanir_signatures":[{"digest":{"line_hashes":["125891005608191820770720877063515235555","316611299361116449666094811952290979834","128216587994527917137212365768304293579","221974358816444001466352480821069488281","3736484218255656514377126541270710995","147025275818387161275454253042588794037","339293208946729552126420443306772256070","117159239386617903839733277221997793612"],"threshold":0.9},"id":"CVE-2024-56169-4656c08c","signature_type":"Line","signature_version":"v1","source":"https://github.com/nicmx/fort-validator/commit/b0914e8cf864dabc99db81d247054e063c71e003","target":{"file":"src/object/certificate.c"},"deprecated":false},{"deprecated":false,"digest":{"line_hashes":["143721449560931799191158835214769215488","57087654008261763998719159489069014322","338290369151923393925060084543590778673","45497942197622468526934548201341809873","328731616568163051924845625805541950514","299441761249121804907079016085885198745","322033195409701495922415129337971157909","284981517908473252261470001461446537595","9824603760609492702629091530989179889"],"threshold":0.9},"id":"CVE-2024-56169-bcdba9cb","signature_type":"Line","signature_version":"v1","source":"https://github.com/nicmx/fort-validator/commit/b0914e8cf864dabc99db81d247054e063c71e003","target":{"file":"src/config.c"}},{"id":"CVE-2024-56169-d452b134","signature_type":"Function","signature_version":"v1","source":"https://github.com/nicmx/fort-validator/commit/b0914e8cf864dabc99db81d247054e063c71e003","target":{"file":"src/config.c","function":"print_usage"},"deprecated":false,"digest":{"function_hash":"125108124420554091507793346910900119124","length":680}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}