​
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-8vfr-f579-h7rf

Published

Last updated

https://images.chainguard.dev/security/CGA-8vfr-f579-h7rf
Package

hey

Latest Update
Fixed
Fixed Version

0.1.4-r3

Aliases
  • CVE-2021-31525
  • GHSA-h86h-8ppg-mxmh

Severity

5.9

Medium

CVSS V3

Summary

golang.org/x/net/http/httpguts vulnerable to Uncontrolled Recursion

Description

golang.org/x/net/http/httpguts in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote attackers to cause a denial of service (panic) via a large header to ReadRequest or ReadResponse. Server, Transport, and Client can each be affected in some configurations.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images