Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

golang.org/x/net : = 0.0.0-20211112202133-69e39bad7dc2 - Non-linear parsing of case-insensitive content in golang.org/x/net/html #3

Open
vincent-goyal opened this issue Feb 11, 2025 · 2 comments

Comments

@vincent-goyal
Copy link

An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This could cause a denial of service.

References:

File Path: go.mod

Mitigation: Patched version: 0.33.0

Finding Id : 305022927

Tool Finding Id: RVA_kwDON3wZgs8AAAABWh2aKw

@vincent-goyal
Copy link
Author

Finding [305022927] status changed to Confirmed
Note:
by [email protected] via ArmorCode Platform

@vincent-goyal
Copy link
Author

The corresponding finding 305022927 is deleted from ArmorCode
by [email protected] via ArmorCode Platform

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant