GHSA-xcf7-q56x-78gh
Dashboard / Vulnerabilities / GHSA-xcf7-q56x-78gh
GHSA-xcf7-q56x-78gh
Summary: github.com/pires/go-proxyproto vulnerable to DoS via Connection descriptor exhaustion
Details: The package `github.com/pires/go-proxyproto` before 0.6.1 is vulnerable to Denial of Service (DoS) via creating connections without the proxy protocol header. While this issue was patched in 0.6.0, the fix introduced additional issues which were subsequently patched in 0.6.1.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-23409, https://github.com/pires/go-proxyproto/issues/65, https://github.com/pires/go-proxyproto/issues/75, https://github.com/pires/go-proxyproto/pull/74, https://github.com/pires/go-proxyproto/pull/74/commits/cdc63867da24fc609b727231f682670d0d1cd346, https://github.com/pires/go-proxyproto/pull/76, https://github.com/pires/go-proxyproto/commit/2e44d7a76a851d66890ab341403253afae5caac2, https://github.com/pires/go-proxyproto, https://github.com/pires/go-proxyproto/releases/tag/v0.6.0, https://github.com/pires/go-proxyproto/releases/tag/v0.6.1, https://pkg.go.dev/vuln/GO-2022-0233, https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMPIRESGOPROXYPROTO-1316439
Affected packages
Package
Name: github.com/pires/go-proxyproto
Purl: pkg:golang/github.com/pires/go-proxyproto
Affected ranges
Type: SEMVER
Events:
