golang.org/x/net/http2 Denial of Service vulnerability
High severity
GitHub Reviewed
Published
Sep 7, 2022
to the GitHub Advisory Database
•
Updated May 20, 2024
Description
Published by the National Vulnerability Database
Sep 6, 2022
Published to the GitHub Advisory Database
Sep 7, 2022
Reviewed
Jan 18, 2023
Last updated
May 20, 2024
In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error.
References