VDB
Sign up
—

GO-2022-0233

Resource exhaustion in github.com/pires/go-proxyproto

Quick fix

GO-2022-0233 — github.com/pires/go-proxyproto: upgrade to the fixed version with the command below.

go get github.com/pires/go-proxyproto@v0.6.1

Details

The PROXY protocol server does not impose a timeout on reading the header from new connections, allowing a malicious client to cause resource exhaustion and a denial of service by opening many connections and sending no data on them.

v0.6.0 of the proxyproto package adds support for a user-defined header timeout. v0.6.1 adds a default timeout of 200ms and v0.6.2 increases the default timeout to 10s.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/pires/go-proxyproto
Introduced in: 0Fixed in: 0.6.1
Fixgo get github.com/pires/go-proxyproto@v0.6.1

References