CVE-2021-31525
27.05.2021, 13:15
net/http in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote attackers to cause a denial of service (panic) via a large header to ReadRequest or ReadResponse. Server, Transport, and Client can each be affected in some configurations.Enginsight
Vendor | Product | Version |
---|---|---|
golang | go | 𝑥 < 1.15.12 |
golang | go | 1.16.0 ≤ 𝑥 < 1.16.4 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
golang-1.11 |
| ||||||||||||||||||||||||
golang-1.15 |
| ||||||||||||||||||||||||
golang-1.16 |
| ||||||||||||||||||||||||
golang-golang-x-net |
| ||||||||||||||||||||||||
golang-golang-x-net-dev |
| ||||||||||||||||||||||||
google-guest-agent |
|
Common Weakness Enumeration
References