GO-2022-0233
Dashboard / Vulnerabilities / GO-2022-0233
GO-2022-0233
Summary: Resource exhaustion in github.com/pires/go-proxyproto
Details: The PROXY protocol server does not impose a timeout on reading the header from new connections, allowing a malicious client to cause resource exhaustion and a denial of service by opening many connections and sending no data on them. v0.6.0 of the proxyproto package adds support for a user-defined header timeout. v0.6.1 adds a default timeout of 200ms and v0.6.2 increases the default timeout to 10s.
References: https://github.com/pires/go-proxyproto/pull/74, https://github.com/pires/go-proxyproto/pull/74/commits/cdc63867da24fc609b727231f682670d0d1cd346, https://github.com/pires/go-proxyproto/issues/65
Affected packages
Package
Name: github.com/pires/go-proxyproto
Purl: pkg:golang/github.com/pires/go-proxyproto
Affected ranges
Type: SEMVER
Events:
