GHSA-4cxw-hq44-r344
Dashboard / Vulnerabilities / GHSA-4cxw-hq44-r344
GHSA-4cxw-hq44-r344
Summary: Off-by-one Error in v2fly/v2ray-core
Details: v2fly/v2ray-core prior to 4.44.0 is vulnerable to an off-by-one error. Indexing operations on arrays, slices, or strings should use an index at most one less than the length. If the index is checked for being less than or equal to the length (`<=`), instead of less than the length (`<`), the index could be out of bounds.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-4070, https://github.com/v2fly/v2ray-core/commit/c1af2bfd7aa59a4482aa7f6ec4b9208c1d350b5c, https://github.com/v2fly/v2ray-core, https://huntr.dev/bounties/8da19456-4d89-41ef-9781-a41efd6a1877
Affected packages
Package
Name: github.com/v2fly/v2ray-core/v4
Purl: pkg:golang/github.com/v2fly/v2ray-core/v4
Affected ranges
Type: SEMVER
Events:
