CVE-2022-25891
Dashboard / Vulnerabilities / CVE-2022-25891
CVE-2022-25891
Summary: Denial of Service (DoS)
Details: The package github.com/containrrr/shoutrrr/pkg/util before 0.6.0 are vulnerable to Denial of Service (DoS) via the util.PartitionMessage function. Exploiting this vulnerability is possible by sending exactly 2000, 4000, or 6000 characters messages.
References: https://github.com/containrrr/shoutrrr/releases/tag/v0.6.0, https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/25xxx/CVE-2022-25891.json, https://nvd.nist.gov/vuln/detail/CVE-2022-25891, https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMCONTAINRRRSHOUTRRRPKGUTIL-2849059, https://github.com/containrrr/shoutrrr/issues/240, https://github.com/containrrr/shoutrrr/commit/6a27056f9d7522a8b493216195cb7634bf4b5c42, https://github.com/containrrr/shoutrrr/pull/242
Affected packages
Package
Name:
Purl:
