VDB
Sign up
—

GO-2022-0322

Uncontrolled resource consumption in github.com/prometheus/client_golang

Quick fix

GO-2022-0322 — github.com/prometheus/client_golang: upgrade to the fixed version with the command below.

go get github.com/prometheus/client_golang@v1.11.1

Details

The Prometheus client_golang HTTP server is vulnerable to a denial of service attack when handling requests with non-standard HTTP methods.

In order to be affected, an instrumented software must use any of the promhttp.InstrumentHandler* middleware except RequestsInFlight; not filter any specific methods (e.g GET) before middleware; pass a metric with a "method" label name to a middleware; and not have any firewall/LB/proxy that filters away requests with unknown "method".

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/prometheus/client_golang
Introduced in: 0Fixed in: 1.11.1
Fixgo get github.com/prometheus/client_golang@v1.11.1

References