[FREEBSD:02E51CB3-D7E4-11ED-9F7A-5404A68AD561] traefik -- Use of vulnerable Go modules net/http, net/textproto

Severity High
Affected Packages 1
CVEs 2

The Go project reports:

  HTTP and MIME header parsing can allocate large amounts
     of memory, even when parsing small inputs, potentially
     leading to a denial of service. Certain unusual patterns
     of input data can cause the common function used to parse
     HTTP and MIME headers to allocate substantially more
     memory than required to hold the parsed headers. An
     attacker can exploit this behavior to cause an HTTP
     server to allocate large amounts of memory from a small
     request, potentially leading to memory exhaustion and a
     denial of service. With fix, header parsing now correctly
     allocates only the memory required to hold parsed headers.
Package Affected Version
pkg:freebsd/traefik < 2.9.9_1
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:freebsd/traefik traefik < 2.9.9_1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...