golang.org/x/net vulnerable to Uncontrolled Resource Consumption

Overview

Source
ID
GHSA-vvpx-j8f3-3w6h
Aliases
BIT-golang-2022-41723
CVE-2022-41723
GO-2023-1571
Affected package

Description

A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.

Summary

119.14k
Total packages affected
Packages with at least one version that is affected by the advisory or has an affected dependency.
14.06k
Packages with a known fix
Packages with versions affected by the advisory that have a greater version that is not affected.
8.89%
Total ecosystem affected
The proportion of packages in the ecosystem that are affected by the advisory (fixed or not).
Affected Version: Introduced: 0, Fixed: 0.7.0
Patched/Unaffected
v0.7.0
v0.8.0
v0.9.0
v0.10.0
v0.11.0
v0.12.0
v0.13.0
v0.14.0
v0.15.0
v0.16.0
v0.17.0
v0.18.0
v0.19.0
v0.20.0
v0.21.0
v0.22.0
v0.23.0
v0.24.0
v0.25.0
v0.26.0
v0.27.0
v0.28.0
v0.29.0
v0.30.0
v0.31.0
v0.32.0
v0.33.0
v0.34.0
v0.35.0
v0.36.0
v0.37.0
Affected
v0.6.0
v0.5.0
v0.4.0
v0.3.0
v0.2.0
v0.1.0