CVE-2021-44716Uncontrolled Resource Consumption in Spiffe Spire

Severity
7.5HIGHNVD
EPSS
0.1%
top 73.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 1
Latest updateNov 1

Description

net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

Gogolang.org/x_net_http2< 0.0.0-20211209124913-491a49abca63
NVDgolang/go1.17.01.17.5+1
Gogolang.org/x_net< 0.0.0-20211209124913-491a49abca63
Gogithub.com/spiffe_spire1.1.01.1.3+1
Palo Altopaloalto/pan-os

Also affects: Debian Linux 9.0

Patches

🔴Vulnerability Details

7
OSV
Unbounded memory growth in net/http and golang.org/x/net/http22022-07-15
GHSA
Unbounded memory usage on exposed HTTP/2 (non-gRPC) endpoints2022-01-12
OSV
Unbounded memory usage on exposed HTTP/2 (non-gRPC) endpoints2022-01-12
OSV
golang.org/x/net/http2 allows uncontrolled memory consumption2022-01-02
GHSA
golang.org/x/net/http2 allows uncontrolled memory consumption2022-01-02

📋Vendor Advisories

5
Palo Alto
PAN-SA-2024-0013 Informational Bulletin: Impact of OSS CVEs in PAN-OS2024-11-01
Red Hat
etcd: Incomplete fix for CVE-2021-44716 in OpenStack Platform2024-05-06
Microsoft
net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests.2022-01-11
Red Hat
golang: net/http: limit growth of header canonicalization cache2021-12-09
Debian
CVE-2021-44716: golang-1.15 - net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memor...2021
CVE-2021-44716 — Uncontrolled Resource Consumption | cvebase