CVE-2022-32149
Denial of service via crafted Accept-Language header in golang.org/x/text/language
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take significant time to parse.
Un atacante podría causar una denegación de servicio al diseñar un encabezado Accept-Language que ParseAcceptLanguage tardaría mucho tiempo en analizar
A vulnerability was found in the golang.org/x/text/language package. An attacker can craft an Accept-Language header which ParseAcceptLanguage will take significant time to parse. This issue leads to a denial of service, and can impact availability.
It was discovered that Go Text incorrectly handled certain encodings. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. It was discovered that Go Text incorrectly handled certain BCP 47 language tags. An attacker could possibly use this issue to cause a denial of service. CVE-2020-28851, CVE-2020-28852, and CVE-2021-38561 affected only Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2022-05-31 CVE Reserved
- 2022-10-14 CVE Published
- 2025-05-15 CVE Updated
- 2025-08-16 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-407: Inefficient Algorithmic Complexity
- CWE-772: Missing Release of Resource after Effective Lifetime
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
https://go.dev/issue/56152 | Issue Tracking | |
https://groups.google.com/g/golang-announce/c/-hjNw559_tE/m/KlGTfid5CAAJ | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://go.dev/cl/442235 | 2022-10-18 | |
https://pkg.go.dev/vuln/GO-2022-1059 | 2022-10-18 | |
https://access.redhat.com/security/cve/CVE-2022-32149 | 2024-04-29 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2134010 | 2024-04-29 |