go-2024-2687
HIGH CVSS 7.5 osv_golang
Description
An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames.
Timeline
- Published
- 2024-04-03 16:00 UTC
- Last Modified
- 2024-04-05
CVSS Details
CVSS details not available.
Affected Products
No product information available.
CVSS metrics
| Version | Base | Severity | Vector | Exploitability | Impact | Source |
|---|---|---|---|---|---|---|
| 3.1 | 7.5 | HIGH | |
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cvss": 7.5,
"datePublished": "2024-04-03T16:00:00Z",
"dateUpdated": "2024-04-05T18:00:00Z",
"description": "An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames.",
"id": "GO-2024-2687",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"version": "3.1"
}
}
]
},
"severity": "HIGH",
"source": "osv_golang",
"title": "Go: net/http HTTP/2 CONTINUATION flood"
}