A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.
2023-02-28T18:15:09.980
2025-05-05T16:15:20.433
Modified
CVSSv3.1: 7.5 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | golang | go | < 1.19.6 | Yes |
Application | golang | go | 1.20.0 | Yes |
Application | golang | hpack | < 0.7.0 | Yes |
Application | golang | http2 | < 0.7.0 | Yes |