Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vvpx-j8f3-3w6h

Опубликовано: 17 фев. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

golang.org/x/net vulnerable to Uncontrolled Resource Consumption

A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.

Пакеты

Наименование

golang.org/x/net

go
Затронутые версииВерсия исправления

< 0.7.0

0.7.0

EPSS

Процентиль: 51%
0.00272
Низкий

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 3 лет назад

A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.

CVSS3: 7.5
redhat
около 3 лет назад

A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.

CVSS3: 7.5
nvd
около 3 лет назад

A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.

CVSS3: 7.5
msrc
около 1 года назад

Denial of service via crafted HTTP/2 stream in net/http and golang.org/x/net

CVSS3: 7.5
debian
около 3 лет назад

A maliciously crafted HTTP/2 stream could cause excessive CPU consumpt ...

EPSS

Процентиль: 51%
0.00272
Низкий

7.5 High

CVSS3

Дефекты

CWE-400