GO-2022-0322
Dashboard / Vulnerabilities / GO-2022-0322
GO-2022-0322
Published: 15 Jul 2022Last Modified: 4 Feb 2026
Summary: Uncontrolled resource consumption in github.com/prometheus/client_golang
Details: The Prometheus client_golang HTTP server is vulnerable to a denial of service attack when handling requests with non-standard HTTP methods. In order to be affected, an instrumented software must use any of the promhttp.InstrumentHandler* middleware except RequestsInFlight; not filter any specific methods (e.g GET) before middleware; pass a metric with a "method" label name to a middleware; and not have any firewall/LB/proxy that filters away requests with unknown "method".
Affected packages
Package
Name: github.com/prometheus/client_golang
Purl: pkg:golang/github.com/prometheus/client_golang
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -1.11.1
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
