—
GO-2022-0233
Resource exhaustion in github.com/pires/go-proxyproto
Quick fix
GO-2022-0233 — github.com/pires/go-proxyproto: upgrade to the fixed version with the command below.
go get github.com/pires/go-proxyproto@v0.6.1Details
The PROXY protocol server does not impose a timeout on reading the header from new connections, allowing a malicious client to cause resource exhaustion and a denial of service by opening many connections and sending no data on them.
v0.6.0 of the proxyproto package adds support for a user-defined header timeout. v0.6.1 adds a default timeout of 200ms and v0.6.2 increases the default timeout to 10s.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/pires/go-proxyproto
Introduced in:
0Fixed in: 0.6.1Fix
go get github.com/pires/go-proxyproto@v0.6.1