Lucene search

K
cvelistMitreCVELIST:CVE-2022-30591
HistoryJul 06, 2022 - 11:19 a.m.

CVE-2022-30591

2022-07-0611:19:21
mitre
www.cve.org
6
quic-go version 0.27.0
denial of service
slowloris
incomplete requests
remote attackers
cpu consumption
mtu discovery
probe timer overflow

EPSS

0.002

Percentile

56.1%

quic-go through 0.27.0 allows remote attackers to cause a denial of service (CPU consumption) via a Slowloris variant in which incomplete QUIC or HTTP/3 requests are sent. This occurs because mtu_discoverer.go misparses the MTU Discovery service and consequently overflows the probe timer. NOTE: the vendor’s position is that this behavior should not be listed as a vulnerability on the CVE List

EPSS

0.002

Percentile

56.1%

Related for CVELIST:CVE-2022-30591