blob: 5f1485ad855c9198d602e4d7f16e1588d61e5d34 [file] [log] [blame]
id: GO-2024-2911
modules:
- module: github.com/mostynb/go-grpc-compression
versions:
- introduced: 1.1.4
- fixed: 1.2.3
vulnerable_at: 1.2.2
summary: go-grpc-compression has a zstd decompression bombing vulnerability in github.com/mostynb/go-grpc-compression
ghsas:
- GHSA-87m9-rv8p-rgmg
references:
- advisory: https://github.com/mostynb/go-grpc-compression/security/advisories/GHSA-87m9-rv8p-rgmg
- fix: https://github.com/mostynb/go-grpc-compression/commit/629c44d3acb9624993cc7de629f47d72109e2ce5
source:
id: GHSA-87m9-rv8p-rgmg
created: 2024-08-16T16:52:01.15802-04:00
review_status: UNREVIEWED