VDB
Sign up
MEDIUM5.9

GHSA-xwh9-gc39-5298

github.com/go-resty/resty/v2 HTTP request body disclosure

Quick fix

GHSA-xwh9-gc39-5298 — github.com/go-resty/resty/v2: upgrade to the fixed version with the command below.

go get github.com/go-resty/resty/v2@v2.11.0

Details

A race condition in go-resty can result in HTTP request body disclosure across requests.

This condition can be triggered by calling sync.Pool.Put with the same *bytes.Buffer more than once, when request retries are enabled and a retry occurs. The call to sync.Pool.Get will then return a bytes.Buffer that hasn't had bytes.Buffer.Reset called on it. This dirty buffer will contain the HTTP request body from an unrelated request, and go-resty will append the current HTTP request body to it, sending two bodies in one request.

The sync.Pool in question is defined at package level scope, so a completely unrelated server could receive the request body.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/go-resty/resty/v2
Introduced in: 2.10.0Fixed in: 2.11.0
Fixgo get github.com/go-resty/resty/v2@v2.11.0

References