Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xrjj-mj9h-534m

Опубликовано: 08 дек. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

golang.org/x/net/http2 vulnerable to possible excessive memory growth

An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending very large keys can cause the server to allocate approximately 64 MiB per open connection.

Ссылки

Пакеты

Наименование

golang.org/x/net/http2

go
Затронутые версииВерсия исправления

< 0.4.0

0.4.0

Наименование

golang.org/x/net

go
Затронутые версииВерсия исправления

< 0.4.0

0.4.0

EPSS

Процентиль: 67%
0.00541
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 3 лет назад

An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending very large keys can cause the server to allocate approximately 64 MiB per open connection.

CVSS3: 5.3
redhat
около 3 лет назад

An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending very large keys can cause the server to allocate approximately 64 MiB per open connection.

CVSS3: 5.3
nvd
около 3 лет назад

An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending very large keys can cause the server to allocate approximately 64 MiB per open connection.

CVSS3: 5.3
msrc
около 3 лет назад

Описание отсутствует

CVSS3: 5.3
debian
около 3 лет назад

An attacker can cause excessive memory growth in a Go server accepting ...

EPSS

Процентиль: 67%
0.00541
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-770