You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Moved to https://github.com/containerd/containerd/tree/master/pkg/cri . If you wish to submit issues/PRs, please submit to https://github.com/containerd/containerd
net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests.
mend-for-github-combot
changed the title
CVE-2021-44716 (High) detected in github.com/golang/net/http2-5ee1b9f4859acd2e99987ef94ec7a58427c53bef
CVE-2021-44716 (High) detected in multiple libraries
Dec 29, 2023
CVE-2021-44716 - High Severity Vulnerability
Vulnerable Libraries - github.com/containerd/cri-v1.11.1-0.20200601160732-d7ce093d63d0, github.com/containerd/containerd-6312b52de5ad8fa5637e6d1a24954b68448303a9, github.com/golang/net/http2-5ee1b9f4859acd2e99987ef94ec7a58427c53bef
github.com/containerd/cri-v1.11.1-0.20200601160732-d7ce093d63d0
Moved to https://github.com/containerd/containerd/tree/master/pkg/cri . If you wish to submit issues/PRs, please submit to https://github.com/containerd/containerd
Library home page: https://proxy.golang.org/github.com/containerd/cri/@v/v1.11.1-0.20200601160732-d7ce093d63d0.zip
Dependency Hierarchy:
github.com/containerd/containerd-6312b52de5ad8fa5637e6d1a24954b68448303a9
An open and reliable container runtime
Library home page: https://proxy.golang.org/github.com/containerd/containerd/@v/v1.4.0-beta.0.0.20200515000003-6312b52de5ad.zip
Dependency Hierarchy:
github.com/golang/net/http2-5ee1b9f4859acd2e99987ef94ec7a58427c53bef
[mirror] Go supplementary network libraries
Dependency Hierarchy:
Found in HEAD commit: d176fc163fbd69f1a628cf9b7ea217423ee02d31
Found in base branch: master
Vulnerability Details
net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests.
Publish Date: 2022-01-01
URL: CVE-2021-44716
CVSS 3 Score Details (7.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: GHSA-vc3p-29h2-gpcp
Release Date: 2022-01-01
Fix Resolution: github.com/golang/net - 491a49abca63de5e07ef554052d180a1b5fe2d70
The text was updated successfully, but these errors were encountered: