{"id":"PYSEC-2026-1489","summary":"Keylime's registrar vulnerable to Denial-of-service attack via a single open connection","details":"### Impact\nKeylime `registrar` is prone to a simple denial of service attack in which an adversary opens a connection to the TLS port (by default, port `8891`) blocking further, legitimate connections. As long as the connection is open, the `registrar` is blocked and cannot serve any further clients (`agents` and `tenants`), which prevents normal operation. The problem does not affect the `verifier`.\n\n### Patches\nUsers should upgrade to release 7.4.0","aliases":["CVE-2023-38200","GHSA-pg75-v6fp-8q59"],"modified":"2026-07-07T17:46:35.187805562Z","published":"2026-07-07T11:45:21.483576Z","references":[{"type":"WEB","url":"https://github.com/keylime/keylime/security/advisories/GHSA-pg75-v6fp-8q59"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-38200"},{"type":"WEB","url":"https://github.com/keylime/keylime/pull/1421"},{"type":"FIX","url":"https://github.com/keylime/keylime/commit/c68d8f0b7ea549c12b6956ab0f3c28ae0360ae17"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2023-38200"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2222692"},{"type":"PACKAGE","url":"https://github.com/keylime/keylime"},{"type":"WEB","url":"https://github.com/keylime/keylime/releases/tag/v7.4.0"},{"type":"PACKAGE","url":"https://pypi.org/project/keylime"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pg75-v6fp-8q59"}],"affected":[{"package":{"name":"keylime","ecosystem":"PyPI","purl":"pkg:pypi/keylime"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.4.0"}]}],"versions":["6.3.1","6.3.2","6.4.0","6.4.1","6.4.2","6.4.3","6.5.0","6.5.1","6.5.2","6.5.3","6.6.0","6.8.0","7.0.0","7.2.5","7.3.0"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/keylime/PYSEC-2026-1489.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}