Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33335
HistoryDec 14, 2021 - 8:52 p.m.

Denial Of Service (DoS)

2021-12-1420:52:35
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
19

0.003 Low

EPSS

Percentile

69.5%

golang is vulnerable to denial of service. The vulnerability exists due to an uncontrolled resource consumption flaw in golang’s net/http library in the canonicalHeader() function which allows an attacker to submits maliciously crafted requests to applications linked with net/http’s http2 functionality and crash the system.