Github.Com Pires Go-Proxyproto vulnerabilities
2 known vulnerabilities affecting github.com/pires_go-proxyproto.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2021-23409P3HIGHCVSS 7.5≥ unspecified, < 0.6.02021-07-21
CVE-2021-23409 [HIGH] CVE-2021-23409: The package github.com/pires/go-proxyproto before 0.6.0 are vulnerable to Denial of Service (DoS) vi
The package github.com/pires/go-proxyproto before 0.6.0 are vulnerable to Denial of Service (DoS) via creating connections without the proxy protocol header.
ghsanvdosv
CVE-2021-23351P4MEDIUMCVSS 4.9≥ unspecified, < 0.5.02021-03-08
CVE-2021-23351 [MEDIUM] CVE-2021-23351: The package github.com/pires/go-proxyproto before 0.5.0 are vulnerable to Denial of Service (DoS) vi
The package github.com/pires/go-proxyproto before 0.5.0 are vulnerable to Denial of Service (DoS) via the parseVersion1() function. The reader in this package is a default bufio.Reader wrapping a net.Conn. It will read from the connection until it finds a newline. Since no limits are implemented in the code, a deliberately malformed V1 header could be used
ghsanvdosv