CVE-2021-23351: Uncontrolled Resource Consumption
(updated )
The package github.com/pires/go-proxyproto is vulnerable to Denial of Service (DoS) via the parseVersion1()
function. The reader in this package is a default bufio.Reader
wrapping a net.Conn
.
References
Detect and mitigate CVE-2021-23351 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →