Denial of service in net/http and golang.org/x/net/http2

Overview

Source
ID
GO-2022-0969
Aliases
BIT-golang-2022-27664
CVE-2022-27664
GHSA-69cg-p879-7622
Affected package

Description

HTTP/2 server connections can hang forever waiting for a clean shutdown that was preempted by a fatal error. This condition can be exploited by a malicious client to cause a denial of service.

Summary

105.55k
Total packages affected
Packages with at least one version that is affected by the advisory or has an affected dependency.
13.14k
Packages with a known fix
Packages with versions affected by the advisory that have a greater version that is not affected.
7.88%
Total ecosystem affected
The proportion of packages in the ecosystem that are affected by the advisory (fixed or not).
Affected Version: Introduced: 0, Fixed: 0.0.0-20220906165146-f3363e06e74c
Patched/Unaffected
v0.1.0
v0.2.0
v0.3.0
v0.4.0
v0.5.0
v0.6.0
v0.7.0
v0.8.0
v0.9.0
v0.10.0
v0.11.0
v0.12.0
v0.13.0
v0.14.0
v0.15.0
v0.16.0
v0.17.0
v0.18.0
v0.19.0
v0.20.0
v0.21.0
v0.22.0
v0.23.0
v0.24.0
v0.25.0
v0.26.0
v0.27.0
v0.28.0
v0.29.0
v0.30.0
v0.31.0
v0.32.0
v0.33.0
v0.34.0
v0.35.0
v0.36.0
v0.37.0
Affected