Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h86h-8ppg-mxmh

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

golang.org/x/net/http/httpguts vulnerable to Uncontrolled Recursion

golang.org/x/net/http/httpguts in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote attackers to cause a denial of service (panic) via a large header to ReadRequest or ReadResponse. Server, Transport, and Client can each be affected in some configurations.

Пакеты

Наименование

golang.org/x/net

go
Затронутые версииВерсия исправления

< 0.0.0-20210428140749-89ef3d95e781

0.0.0-20210428140749-89ef3d95e781

EPSS

Процентиль: 1%
0.0001
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-674

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 4 лет назад

net/http in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote attackers to cause a denial of service (panic) via a large header to ReadRequest or ReadResponse. Server, Transport, and Client can each be affected in some configurations.

CVSS3: 5.9
redhat
около 4 лет назад

net/http in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote attackers to cause a denial of service (panic) via a large header to ReadRequest or ReadResponse. Server, Transport, and Client can each be affected in some configurations.

CVSS3: 5.9
nvd
около 4 лет назад

net/http in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote attackers to cause a denial of service (panic) via a large header to ReadRequest or ReadResponse. Server, Transport, and Client can each be affected in some configurations.

CVSS3: 5.9
msrc
около 4 лет назад

Описание отсутствует

CVSS3: 5.9
debian
около 4 лет назад

net/http in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote a ...

EPSS

Процентиль: 1%
0.0001
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-674