go-2024-2687

HIGH CVSS 7.5 osv_golang
Description

An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames.

Timeline
Published
2024-04-03 16:00 UTC
Last Modified
2024-04-05
CVSS Details

CVSS details not available.

Affected Products

No product information available.

CVSS metrics
Version Base Severity Vector Exploitability Impact Source
3.1 7.5 HIGH
References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cvss": 7.5,
  "datePublished": "2024-04-03T16:00:00Z",
  "dateUpdated": "2024-04-05T18:00:00Z",
  "description": "An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames.",
  "id": "GO-2024-2687",
  "metrics": {
    "cvssMetricV31": [
      {
        "cvssData": {
          "baseScore": 7.5,
          "baseSeverity": "HIGH",
          "version": "3.1"
        }
      }
    ]
  },
  "severity": "HIGH",
  "source": "osv_golang",
  "title": "Go: net/http HTTP/2 CONTINUATION flood"
}
View JSON API Download JSON