VDB
Sign up
HIGH7.5

PYSEC-2026-1489

Keylime's registrar vulnerable to Denial-of-service attack via a single open connection

Quick fix

PYSEC-2026-1489 — keylime: upgrade to the fixed version with the command below.

pip install --upgrade 'keylime>=7.4.0'

Details

### Impact Keylime `registrar` is prone to a simple denial of service attack in which an adversary opens a connection to the TLS port (by default, port `8891`) blocking further, legitimate connections. As long as the connection is open, the `registrar` is blocked and cannot serve any further clients (`agents` and `tenants`), which prevents normal operation. The problem does not affect the `verifier`.

### Patches Users should upgrade to release 7.4.0

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/keylime
Introduced in: 0Fixed in: 7.4.0
Fixpip install --upgrade 'keylime>=7.4.0'

References