CVE-2022-41717
ADVISORY - githubSummary
An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending very large keys can cause the server to allocate approximately 64 MiB per open connection.
Common Weakness Enumeration (CWE)
Allocation of Resources Without Limits or Throttling
Allocation of Resources Without Limits or Throttling
Allocation of Resources Without Limits or Throttling
GoLang
-
| Package | Type | OS Name | OS Version | Affected Ranges | Fix Versions |
|---|---|---|---|---|---|
| stdlib | golang | - | - | >=1.19.0-0,<1.19.4 | 1.19.4 |
| golang.org/x/net | golang | - | - | <0.4.0 | 0.4.0 |
| stdlib | golang | - | - | <1.18.9 | 1.18.9 |
Severity and metrics
No CVSS data available from this advisory.
NIST
3.9
CVSS SCORE
5.3mediumGitHub
3.9
CVSS SCORE
5.3mediumAlpine
-
Debian
-
Ubuntu
3.9
CVSS SCORE
5.3mediumAlma
-
CVSS SCORE
N/AmediumAlma
-
CVSS SCORE
N/AmediumAlma
-
CVSS SCORE
N/AmediumAlma
-
CVSS SCORE
N/AmediumAlma
-
CVSS SCORE
N/AmediumAlma
-
CVSS SCORE
N/AmediumAlma
-
CVSS SCORE
N/AmediumAlma
-
CVSS SCORE
N/AmediumAlma
-
CVSS SCORE
N/AmediumAlma
-
CVSS SCORE
N/AmediumAlma
-
CVSS SCORE
N/AmediumAlma
-
CVSS SCORE
N/AmediumAlma
-
CVSS SCORE
N/AmediumAmazon
-
CVSS SCORE
N/AhighAmazon
-
CVSS SCORE
N/AhighAmazon
-
CVSS SCORE
N/AmediumAmazon
-
CVSS SCORE
N/AhighBitnami
BIT-2022-41717
-
CVSS SCORE
N/AmediumBitnami
BIT-golang-2022-41717
3.9
CVSS SCORE
5.3mediumRed Hat
3.9
CVSS SCORE
5.3mediumRocky
-
CVSS SCORE
N/AlowRocky
-
CVSS SCORE
N/AlowRocky
-
CVSS SCORE
N/AhighOracle
-
CVSS SCORE
N/AhighOracle
-
CVSS SCORE
N/AmediumOracle
-
CVSS SCORE
N/AmediumOracle
-
CVSS SCORE
N/AmediumOracle
-
CVSS SCORE
N/AmediumOracle
-
CVSS SCORE
N/AmediumOracle
-
CVSS SCORE
N/AmediumOracle
-
CVSS SCORE
N/AmediumOracle
-
CVSS SCORE
N/AmediumOracle
-
CVSS SCORE
N/AmediumOracle
-
CVSS SCORE
N/AmediumOracle
-
CVSS SCORE
N/AmediumOracle
-
CVSS SCORE
N/AmediumChainguard
CGA-2x78-74wr-p72f
-
Chainguard
CGA-4mvv-5m7x-77gv
-
Chainguard
CGA-cqw2-v954-rhw8
-
Chainguard
CGA-r3fc-qhc2-3jv5
-
Chainguard
CGA-wfjc-f2gc-896v
-
Chainguard
CGA-x89c-xvp8-rp65
-