A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.
References
Link | Resource |
---|---|
https://go.dev/cl/468135 | Patch |
https://go.dev/issue/57855 | Issue Tracking |
https://go.dev/cl/468295 | Patch |
https://pkg.go.dev/vuln/GO-2023-1571 | Vendor Advisory |
https://groups.google.com/g/golang-announce/c/V0aBFqaFs_E | Mailing List Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2023-02-28 10:15
Updated : 2023-03-09 08:36
NVD link : CVE-2022-41723
Mitre link : CVE-2022-41723
JSON object : View
CWE
CWE-400
Uncontrolled Resource Consumption
Products Affected
golang
- go
- hpack
- http2