github.com/pires/go-proxyproto vulnerable to DoS via Connection descriptor exhaustion
High severity
GitHub Reviewed
Published
Jul 26, 2021
to the GitHub Advisory Database
•
Updated Aug 30, 2023
Description
Published by the National Vulnerability Database
Jul 21, 2021
Reviewed
Jul 26, 2021
Published to the GitHub Advisory Database
Jul 26, 2021
Last updated
Aug 30, 2023
The package
github.com/pires/go-proxyproto
before 0.6.1 is vulnerable to Denial of Service (DoS) via creating connections without the proxy protocol header. While this issue was patched in 0.6.0, the fix introduced additional issues which were subsequently patched in 0.6.1.References