GHSA-8xc6-g8xw-h2c4
YARP Denial of Service Vulnerability
Quick fix
GHSA-8xc6-g8xw-h2c4 — Yarp.ReverseProxy: upgrade to the fixed version with the command below.
dotnet add package Yarp.ReverseProxy --version 1.0.1Details
### Impact
A denial of service vulnerability exists in how YARP processes input.
### Patches
If you're using YARP `1.0.0`, you should update to NuGet package version [`1.0.1`](https://www.nuget.org/packages/Yarp.ReverseProxy/1.0.1). If you're using YARP `1.1.0-RC.1`, you should update to NuGet package version [`1.1.0-rc.1.22211.2`](https://www.nuget.org/packages/Yarp.ReverseProxy/1.1.0-rc.1.22211.2).
You can do so by updating the `PackageReference` in your `.csproj` file ```diff <ItemGroup> - <PackageReference Include="Yarp.ReverseProxy" Version="1.0.0" /> - <PackageReference Include="Yarp.Telemetry.Consumption" Version="1.0.0" /> + <PackageReference Include="Yarp.ReverseProxy" Version="1.0.1" /> + <PackageReference Include="Yarp.Telemetry.Consumption" Version="1.0.1" /> </ItemGroup> ``` or by selecting `1.0.1` in the NuGet UI inside Visual Studio (`Manage NuGet Packages` / `Updates`) 
### References
[CVE-2022-26924](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26924)
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 1.0.1dotnet add package Yarp.ReverseProxy --version 1.0.11.1.0-rc.1.22152.1Fixed in: 1.1.0-rc.1.22211.2dotnet add package Yarp.ReverseProxy --version 1.1.0-rc.1.22211.2References
- https://github.com/microsoft/reverse-proxy/security/advisories/GHSA-8xc6-g8xw-h2c4[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2022-26924[ADVISORY]
- https://github.com/microsoft/reverse-proxy/commit/11e6272da17beb03d0b44a19d3c4f1ffa52b7c38[WEB]
- https://github.com/microsoft/reverse-proxy[PACKAGE]
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26924[WEB]
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-26924[WEB]