VDB
Sign up
MEDIUM5.9

GHSA-h86h-8ppg-mxmh

golang.org/x/net/http/httpguts vulnerable to Uncontrolled Recursion

Quick fix

GHSA-h86h-8ppg-mxmh — golang.org/x/net: upgrade to the fixed version with the command below.

go get golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781

Details

golang.org/x/net/http/httpguts in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote attackers to cause a denial of service (panic) via a large header to ReadRequest or ReadResponse. Server, Transport, and Client can each be affected in some configurations.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/golang.org/x/net
Introduced in: 0Fixed in: 0.0.0-20210428140749-89ef3d95e781
Fixgo get golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781

References