Closed
Description
CVE-2022-27664 references std, which may be a Go module.
Description:
In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error.
References:
- NIST: https://nvd.nist.gov/vuln/detail/CVE-2022-27664
- JSON: https://github.com/CVEProject/cvelist/tree/254b752b4038217c60cafb31ec8f874c04c64039/2022/27xxx/CVE-2022-27664.json
- web: https://groups.google.com/g/golang-announce
- web: https://groups.google.com/g/golang-announce/c/x49AQzIVX-s
- Imported by: https://pkg.go.dev/std?tab=importedby
See doc/triage.md for instructions on how to triage this report.
modules:
- module: std
packages:
- package: std
description: |
In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error.
cves:
- CVE-2022-27664
references:
- web: https://groups.google.com/g/golang-announce
- web: https://groups.google.com/g/golang-announce/c/x49AQzIVX-s
Metadata
Metadata
Assignees
Type
Projects
Status
Done