{
  "from_raw": "Colm O hEigeartaigh <coheigea@apache.org>",
  "from": "Colm O hEigeartaigh <co...@apache.org>",
  "gravatar": "7760700ec800e9fa0453ac51f2db8802",
  "to": "an...@apache.org,\n de...@directory.apache.org",
  "subject": "CVE-2026-57914: Apache Kerby: StackOverflow on parsing deeply nested ASN1 structures",
  "message-id": "<3c1ce384-6fb0-1db1-04ea-bbc0274b2d96@apache.org>",
  "mid": "cm1pzm66cm7zlsoh9v8fvfg3wzc2yzg6",
  "permalinks": [
    "cm1pzm66cm7zlsoh9v8fvfg3wzc2yzg6",
    "r8c615761a2b20b895061870578bc0b66c9fb1047f6039f34edea4853@<announce.apache.org>"
  ],
  "dbid": "e78be04caaff95bccc71c75b32ce9fcf2cf6b5f0e5c65e2b8ef97859a5fbc301",
  "cc": "de...@directory.apache.org",
  "epoch": 1782470056,
  "list": "<announce.apache.org>",
  "list_raw": "<announce.apache.org>",
  "date": "2026/06/26 10:34:16",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: moderate \n\nAffected versions:\n\n- Apache Kerby (org.apache.kerby:kerby-asn1) before 2.1.2\n\nDescription:\n\nBy sending a deeply nested ASN1 structure to a Apache Kerby client or service, it's possible to trigger a StackOverFlow Exception which can lead to denial of service issues. Users are recommended to upgrade to version 2.1.2, which fixes this issue.\n\nReferences:\n\nhttps://directory.apache.org/\nhttps://www.cve.org/CVERecord?id=CVE-2026-57914\n\n",
  "body_short": "Severity: moderate \n\nAffected versions:\n\n- Apache Kerby (org.apache.kerby:kerby-asn1) before 2.1.2\n\nDescription:\n\nBy sending a deeply nested ASN1 structure to a Apache Kerby client or service, it's pos",
  "html_source_only": false,
  "attachments": [],
  "forum": "announce@apache.org",
  "size": 2417,
  "id": "cm1pzm66cm7zlsoh9v8fvfg3wzc2yzg6"
}