VDB
Sign up
—

GO-2023-1602

Denial of service via deflate decompression bomb in github.com/russellhaering/gosaml2

Quick fix

GO-2023-1602 — github.com/russellhaering/gosaml2: upgrade to the fixed version with the command below.

go get github.com/russellhaering/gosaml2@v0.9.0

Details

A bug in SAML authentication library can result in Denial of Service attacks.

Attackers can craft a "deflate"-compressed request which will consume significantly more memory during processing than the size of the original request. This may eventually lead to memory exhaustion and the process being killed.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/russellhaering/gosaml2
Introduced in: 0Fixed in: 0.9.0
Fixgo get github.com/russellhaering/gosaml2@v0.9.0

References