// For flags

CVE-2022-41723

Denial of service via crafted HTTP/2 stream in net/http and golang.org/x/net

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.

A flaw was found in golang. A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of requests.

*Credits: Philippe Antoine (Catena cyber)
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-09-28 CVE Reserved
  • 2023-02-28 CVE Published
  • 2024-08-03 CVE Updated
  • 2024-10-19 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-400: Uncontrolled Resource Consumption
CAPEC
References (16)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Golang
Search vendor "Golang"
Go
Search vendor "Golang" for product "Go"
< 1.19.6
Search vendor "Golang" for product "Go" and version " < 1.19.6"
-
Affected
Golang
Search vendor "Golang"
Go
Search vendor "Golang" for product "Go"
1.20.0
Search vendor "Golang" for product "Go" and version "1.20.0"
-
Affected
Golang
Search vendor "Golang"
Hpack
Search vendor "Golang" for product "Hpack"
< 0.7.0
Search vendor "Golang" for product "Hpack" and version " < 0.7.0"
go
Affected
Golang
Search vendor "Golang"
Http2
Search vendor "Golang" for product "Http2"
< 0.7.0
Search vendor "Golang" for product "Http2" and version " < 0.7.0"
go
Affected