blob: 9172e1968e85343a8ff37e5f5087d6f0438be7c1 [file] [log] [blame]
packages:
- module: std
package: net/http
symbols:
- http2serverConn.canonicalHeader
versions:
- fixed: 1.16.12
- introduced: 1.17.0
fixed: 1.17.5
vulnerable_at: 1.17.4
- module: golang.org/x/net
package: golang.org/x/net/http2
symbols:
- serverConn.canonicalHeader
derived_symbols:
- Server.ServeConn
versions:
- fixed: 0.0.0-20211209124913-491a49abca63
vulnerable_at: 0.0.0-20211208012354-db4efeb81f4b
description: |
An attacker can cause unbounded memory growth in servers accepting
HTTP/2 requests.
cves:
- CVE-2021-44716
credit: murakmii
links:
pr: https://go.dev/cl/369794
context:
- https://go.dev/issue/50058
- https://groups.google.com/g/golang-announce/c/hcmEScgc00k