Vulnerability CVE-2021-31525: Information

Description

net/http in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote attackers to cause a denial of service (panic) via a large header to ReadRequest or ReadResponse. Server, Transport, and Client can each be affected in some configurations.

Severity: MEDIUM (5.9) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Published: May 27, 2021
Modified: Nov. 7, 2023
Error type identifier: CWE-674

Fixed packages

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://github.com/golang/go/issues/45710
  • Issue Tracking
  • Patch
  • Third Party Advisory
https://groups.google.com/g/golang-announce/c/cu9SP4eSXMc
  • Mailing List
  • Third Party Advisory
GLSA-202208-02
  • Third Party Advisory
FEDORA-2021-ee3c072cd0
      1. Configuration 1

        cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
        Start including
        1.16.0
        End excliding
        1.16.4

        cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
        End excliding
        1.15.12

        Configuration 2

        cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*