HIGH 7.5 Go

golang.org/x/net/http2 Denial of Service vulnerability

GHSA-69cg-p879-7622 · BIT-golang-2022-27664 · CVE-2022-27664 · GO-2022-0969

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error.

Ready to move

Start Securing

Free, no credit card | First findings in minutes