QID 995570

Date Published: 2023-10-17

QID 995570: GO (Go) Security Update for golang.org/x/net (GHSA-qppj-fm5r-hxr3)

swift-nio-http2 is vulnerable to a denial-of-service vulnerability in which a malicious client can create and then reset a large number of HTTP/2 streams in a short period of time. This causes swift-nio-http2 to commit to a large amount of expensive work which it then throws away, including creating entirely new Channels to serve the traffic. This can easily overwhelm an EventLoop and prevent it from making forward progress.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-qppj-fm5r-hxr3 for updates and patch information.
    Vendor References

    CVEs related to QID 995570

    Software Advisories
    Advisory ID Software Component Link
    GHSA-qppj-fm5r-hxr3 golang.org/x/net URL Logo github.com/advisories/GHSA-qppj-fm5r-hxr3