摘要:
net/http in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote attackers to cause a denial of service (panic) via a large header to ReadRequest or ReadResponse. Server, Transport, and Client can each be affected in some configurations.
安全等级: Low
公告ID: KylinSec-SA-2022-2461
发布日期: 2022年9月30日
关联CVE: CVE-2021-31525
net/http in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote attackers to cause a denial of service (panic) via a large header to ReadRequest or ReadResponse. Server, Transport, and Client can each be affected in some configurations.
cve名称 | 产品 | 组件 | 是否受影响 |
---|---|---|---|
CVE-2021-31525 | KY3.4-4A | golang | Unaffected |