UNKNOWN Go
Denial of service from HTTP/2 Rapid Reset in google.golang.org/grpc
GO-2023-2153 · GHSA-m425-mq94-257g
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
An attacker can send HTTP/2 requests, cancel them, and send subsequent requests. This is valid by the HTTP/2 protocol, but would cause the gRPC-Go server to launch more concurrent method handlers than the configured maximum stream limit, grpc.MaxConcurrentStreams. This results in a denial of service due to resource consumption.
Ready to move
Start Securing
Free, no credit card | First findings in minutes