—
GO-2022-0322
Uncontrolled resource consumption in github.com/prometheus/client_golang
Quick fix
GO-2022-0322 — github.com/prometheus/client_golang: upgrade to the fixed version with the command below.
go get github.com/prometheus/client_golang@v1.11.1Details
The Prometheus client_golang HTTP server is vulnerable to a denial of service attack when handling requests with non-standard HTTP methods.
In order to be affected, an instrumented software must use any of the promhttp.InstrumentHandler* middleware except RequestsInFlight; not filter any specific methods (e.g GET) before middleware; pass a metric with a "method" label name to a middleware; and not have any firewall/LB/proxy that filters away requests with unknown "method".
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/prometheus/client_golang
Introduced in:
0Fixed in: 1.11.1Fix
go get github.com/prometheus/client_golang@v1.11.1