Skip to content

x/vulndb: potential Go vuln in net/http: CVE-2022-41723 #1571

Closed
@tatianab

Description

@tatianab

CVE ID

No response

GHSA ID

No response

Additional information

net/http: avoid quadratic complexity in HPACK decoding

A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.

This issue is also fixed in golang.org/x/net/http2 v0.7.0, for users manually configuring HTTP/2.

Thanks to Philippe Antoine (Catena cyber) for reporting this issue.

This is CVE-2022-41723 and Go issue https://go.dev/issue/57855.

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions