Malicious RSA Keys Can Exhaust Server Compute Resources, Researcher Opens Source Test Suite
jedisct1 · x · 2026-07-30
Security researcher jedisct1 updated a GitHub repository called badrsa, featuring a set of synthetic RSA keys designed to trigger pathological behavior and consume excessive resources.
Vulnerability Mechanism:
- Under default OpenSSL providers, normal PEM key-loading APIs load these malicious keys and return an EVPPKEY.
- Key loading and key validation are separate API calls, and loading does not enforce application-specific size or cost limits.
- Applications accepting untrusted key inputs without additional checks may incur massive, unexpected CPU and memory costs during subsequent signing, verification, or encryption operations, potentially leading to Denial of Service (DoS).
More from Safety
- Technologies for Verifying Claims About Frontier AI Training — gleech · 2026-07-30
- AI Safety Focus: Lab Automation Threats and the AST Framework — davidmanheim · 2026-07-30
- Stanford HAI Report: Governing AI Beyond Language in the World Model Era — HooverInstitution · 2026-07-30
- xAI Sues Minnesota Over AI Nudification Law, Defending Grok's Image Generation — ivan_bezdomny · 2026-07-30
- Anthropic Destructively Scanned Millions of Books to Legally Avoid Piracy Claims — soulbeddu · 2026-07-30
- Behind Anthropic's Copyright Controversy: The Publishing Industry is the Real Knowledge Gatekeeper — _akpiper · 2026-07-30