Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability in golang.org/x/net/http2 version < 0.23.0 #3944

Closed
yinonel opened this issue May 1, 2024 · 3 comments
Closed

Vulnerability in golang.org/x/net/http2 version < 0.23.0 #3944

yinonel opened this issue May 1, 2024 · 3 comments

Comments

@yinonel
Copy link

yinonel commented May 1, 2024

https://security.snyk.io/vuln/SNYK-GOLANG-GOLANGORGXNETHTTP2-6531285
This issue is caused by the usage of package golang.org/x/net/http2 in version < 0.23.0.
Vulnerability is allocation of resources without limits or throttling

  • gin version (or commit ref): 1.9.1
@LuizWeitz
Copy link

Hi @yinonel, please check this PL #3920, the code update is done, but await approved!

@codespearhead
Copy link
Contributor

@yinonel Can you close this now that #3950 was merged?

@appleboy appleboy closed this as completed May 7, 2024
@appleboy
Copy link
Member

appleboy commented May 7, 2024

Fixed in v1.10.0 version.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants