VDB
Sign up
HIGH7.5

GHSA-vvpx-j8f3-3w6h

golang.org/x/net vulnerable to Uncontrolled Resource Consumption

Quick fix

GHSA-vvpx-j8f3-3w6h — golang.org/x/net: upgrade to the fixed version with the command below.

go get golang.org/x/net@v0.7.0

Details

A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/golang.org/x/net
Introduced in: 0Fixed in: 0.7.0
Fixgo get golang.org/x/net@v0.7.0

References