Lucene search

K
osvGoogleOSV:GHSA-VC3P-29H2-GPCP
HistoryJan 02, 2022 - 12:00 a.m.

golang.org/x/net/http2 allows uncontrolled memory consumption

2022-01-0200:00:48
Google
osv.dev
12

0.003 Low

EPSS

Percentile

69.5%

net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests.