Unbounded memory growth in net/http and golang.org/x/net/http2
Overview
Source
ID
GO-2022-0288
Aliases
BIT-golang-2021-44716
CVE-2021-44716
GHSA-vc3p-29h2-gpcp
Affected package
Description
An attacker can cause unbounded memory growth in servers accepting HTTP/2 requests.
Summary
87.46k
Total packages affected
help_outline
Packages with at least one version that is affected by the advisory or has an affected dependency.
11.41k
Packages with a known fix
help_outline
Packages with versions affected by the advisory that have a greater version that is not affected.
6.64%
Total ecosystem affected
help_outline
The proportion of packages in the ecosystem that are affected by the advisory (fixed or not).
Affected Version: Introduced: 0, Fixed: 0.0.0-20211209124913-491a49abca63
Patched/Unaffected
Affected