UNKNOWN Go

Denial of service from HTTP/2 Rapid Reset in google.golang.org/grpc

GO-2023-2153 · GHSA-m425-mq94-257g

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

An attacker can send HTTP/2 requests, cancel them, and send subsequent requests. This is valid by the HTTP/2 protocol, but would cause the gRPC-Go server to launch more concurrent method handlers than the configured maximum stream limit, grpc.MaxConcurrentStreams. This results in a denial of service due to resource consumption.

Ready to move

Start Securing

Free, no credit card | First findings in minutes