golang.org/x/net vulnerable to Uncontrolled Resource Consumption
Overview
Source
ID
GHSA-vvpx-j8f3-3w6h
Aliases
BIT-golang-2022-41723
CVE-2022-41723
GO-2023-1571
Affected package
Description
A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.
Impact
Severity
help_outline
Latest version of the CVSS score reported by the source of the advisory.
7.5 HIGH
Reference links
Summary
119.14k
Total packages affected
help_outline
Packages with at least one version that is affected by the advisory or has an affected dependency.
14.06k
Packages with a known fix
help_outline
Packages with versions affected by the advisory that have a greater version that is not affected.
8.89%
Total ecosystem affected
help_outline
The proportion of packages in the ecosystem that are affected by the advisory (fixed or not).
Affected Version: Introduced: 0, Fixed: 0.7.0
Patched/Unaffected
Affected