Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gm9r-q53w-2gh4

Опубликовано: 28 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.

The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.

EPSS

Процентиль: 9%
0.00032
Низкий

7.5 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 месяцев назад

The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.

CVSS3: 7.5
redhat
около 2 месяцев назад

The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.

CVSS3: 7.5
nvd
около 2 месяцев назад

The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.

CVSS3: 7.5
debian
около 2 месяцев назад

The net/url package does not set a limit on the number of query parame ...

rocky
21 день назад

Important: go-rpm-macros security update

EPSS

Процентиль: 9%
0.00032
Низкий

7.5 High

CVSS3

Дефекты

CWE-770