Denial of service in net/http and golang.org/x/net/http2
Overview
Source
ID
GO-2022-0969
Aliases
BIT-golang-2022-27664
CVE-2022-27664
GHSA-69cg-p879-7622
Affected package
Description
HTTP/2 server connections can hang forever waiting for a clean shutdown that was preempted by a fatal error. This condition can be exploited by a malicious client to cause a denial of service.
Summary
105.33k
Total packages affected
help_outline
Packages with at least one version that is affected by the advisory or has an affected dependency.
12.99k
Packages with a known fix
help_outline
Packages with versions affected by the advisory that have a greater version that is not affected.
8.00%
Total ecosystem affected
help_outline
The proportion of packages in the ecosystem that are affected by the advisory (fixed or not).
Affected Version: Introduced: 0, Fixed: 0.0.0-20220906165146-f3363e06e74c
Patched/Unaffected
Affected