CVE-2021-23409
published 2021-07-21CVE-2021-23409: The package github.com/pires/go-proxyproto before 0.6.0 are vulnerable to Denial of Service (DoS) via creating connections without the proxy protocol header.
PriorityP335high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.65%
74.2th percentile
The package github.com/pires/go-proxyproto before 0.6.0 are vulnerable to Denial of Service (DoS) via creating connections without the proxy protocol header.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | golang-github-pires-go-proxyproto | < golang-github-pires-go-proxyproto 0.4.2-2 (bookworm) | golang-github-pires-go-proxyproto 0.4.2-2 (bookworm) |
| github.com | pires_go-proxyproto | >= 0 < 0.6.1 | 0.6.1 |
| github.com | pires_go-proxyproto | >= unspecified < 0.6.0 | 0.6.0 |
| go-proxyproto_project | go-proxyproto | < 0.6.0 | 0.6.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Resource exhaustion in github.com/pires/go-proxyproto
osv·2022-07-01
CVE-2021-23409 Resource exhaustion in github.com/pires/go-proxyproto
Resource exhaustion in github.com/pires/go-proxyproto
The PROXY protocol server does not impose a timeout on reading the header from new connections, allowing a malicious client to cause resource exhaustion and a denial of service by opening many connections and sending no data on them.
v0.6.0 of the proxyproto package adds support for a user-defined header timeout. v0.6.1 adds a default timeout of 200ms and v0.6.2 increases the default timeout to 10s.
GHSA
github.com/pires/go-proxyproto vulnerable to DoS via Connection descriptor exhaustion
ghsa·2021-07-26
CVE-2021-23409 [HIGH] CWE-400 github.com/pires/go-proxyproto vulnerable to DoS via Connection descriptor exhaustion
github.com/pires/go-proxyproto vulnerable to DoS via Connection descriptor exhaustion
The package `github.com/pires/go-proxyproto` before 0.6.1 is vulnerable to Denial of Service (DoS) via creating connections without the proxy protocol header. While this issue was patched in 0.6.0, the fix introduced additional issues which were subsequently patched in 0.6.1.
OSV
github.com/pires/go-proxyproto vulnerable to DoS via Connection descriptor exhaustion
osv·2021-07-26
CVE-2021-23409 [HIGH] github.com/pires/go-proxyproto vulnerable to DoS via Connection descriptor exhaustion
github.com/pires/go-proxyproto vulnerable to DoS via Connection descriptor exhaustion
The package `github.com/pires/go-proxyproto` before 0.6.1 is vulnerable to Denial of Service (DoS) via creating connections without the proxy protocol header. While this issue was patched in 0.6.0, the fix introduced additional issues which were subsequently patched in 0.6.1.
OSV
CVE-2021-23409: The package github
osv·2021-07-21·CVSS 7.5
CVE-2021-23409 [HIGH] CVE-2021-23409: The package github
The package github.com/pires/go-proxyproto before 0.6.0 are vulnerable to Denial of Service (DoS) via creating connections without the proxy protocol header.
Debian
CVE-2021-23409: golang-github-pires-go-proxyproto - The package github.com/pires/go-proxyproto before 0.6.0 are vulnerable to Denial...
vendor_debian·2021·CVSS 7.5
CVE-2021-23409 [HIGH] CVE-2021-23409: golang-github-pires-go-proxyproto - The package github.com/pires/go-proxyproto before 0.6.0 are vulnerable to Denial...
The package github.com/pires/go-proxyproto before 0.6.0 are vulnerable to Denial of Service (DoS) via creating connections without the proxy protocol header.
Scope: local
bookworm: resolved (fixed in 0.4.2-2)
bullseye: open
forky: resolved (fixed in 0.4.2-2)
sid: resolved (fixed in 0.4.2-2)
trixie: resolved (fixed in 0.4.2-2)
No detection rules found.
No writeups or analysis indexed.
https://github.com/pires/go-proxyproto/issues/65https://github.com/pires/go-proxyproto/pull/74https://github.com/pires/go-proxyproto/pull/74/commits/cdc63867da24fc609b727231f682670d0d1cd346https://github.com/pires/go-proxyproto/releases/tag/v0.6.0https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMPIRESGOPROXYPROTO-1316439https://github.com/pires/go-proxyproto/issues/65https://github.com/pires/go-proxyproto/pull/74https://github.com/pires/go-proxyproto/pull/74/commits/cdc63867da24fc609b727231f682670d0d1cd346https://github.com/pires/go-proxyproto/releases/tag/v0.6.0https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMPIRESGOPROXYPROTO-1316439
2021-07-21
Published