MEDIUM5.9
GHSA-h86h-8ppg-mxmh
golang.org/x/net/http/httpguts vulnerable to Uncontrolled Recursion
Quick fix
GHSA-h86h-8ppg-mxmh — golang.org/x/net: upgrade to the fixed version with the command below.
go get golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781Details
golang.org/x/net/http/httpguts in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote attackers to cause a denial of service (panic) via a large header to ReadRequest or ReadResponse. Server, Transport, and Client can each be affected in some configurations.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/golang.org/x/net
Introduced in:
0Fixed in: 0.0.0-20210428140749-89ef3d95e781Fix
go get golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781References
- https://nvd.nist.gov/vuln/detail/CVE-2021-31525[ADVISORY]
- https://github.com/golang/go/issues/45710[WEB]
- https://github.com/golang/go[PACKAGE]
- https://go.dev/cl/313069[WEB]
- https://go.dev/issue/45710[WEB]
- https://go.googlesource.com/net/+/89ef3d95e781148a0951956029c92a211477f7f9[WEB]
- https://groups.google.com/g/golang-announce/c/cu9SP4eSXMc[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ISRZZ6NY5R2TBYE72KZFOCO25TEUQTBF[WEB]
- https://pkg.go.dev/vuln/GO-2022-0236[WEB]
- https://security.gentoo.org/glsa/202208-02[WEB]