—
GO-2023-1602
Denial of service via deflate decompression bomb in github.com/russellhaering/gosaml2
Quick fix
GO-2023-1602 — github.com/russellhaering/gosaml2: upgrade to the fixed version with the command below.
go get github.com/russellhaering/gosaml2@v0.9.0Details
A bug in SAML authentication library can result in Denial of Service attacks.
Attackers can craft a "deflate"-compressed request which will consume significantly more memory during processing than the size of the original request. This may eventually lead to memory exhaustion and the process being killed.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/russellhaering/gosaml2
Introduced in:
0Fixed in: 0.9.0Fix
go get github.com/russellhaering/gosaml2@v0.9.0