[GO-2022-1059] Denial of service via crafted Accept-Language header in golang.org/x/text/language
Severity
High
Affected Packages
1
Fixed Packages
1
CVEs
1
An attacker may cause a denial of service by crafting an Accept-Language header
which ParseAcceptLanguage will take significant time to parse.
Package | Affected Version |
---|---|
pkg:golang/golang.org/x/text/language | >= 0.3.7, < 0.3.8 |
Package | Fixed Version |
---|---|
pkg:golang/golang.org/x/text/language | = 0.3.8 |
- ID
- GO-2022-1059
- Severity
- high
- Severity from
- CVE-2022-32149
- URL
- https://pkg.go.dev/vuln/GO-2022-1059
- Published
-
2022-10-11T17:54:27
(23 months ago) - Modified
-
2024-05-14T19:19:00
(4 months ago) - Other Advisories
Source | # ID | Name | URL |
---|---|---|---|
Security Advisory | https://github.com/advisories/GHSA-69ch-w2m2-3vjp |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |