Vulnerability Report: GO-2024-2958
- CVE-2024-37298, GHSA-3669-72x9-r9p3
- Affects: github.com/gorilla/schema
- Published: Jul 02, 2024
Potential memory exhaustion attack due to sparse slice deserialization in github.com/gorilla/schema
For detailed information about this vulnerability, visit https://github.com/gorilla/schema/security/advisories/GHSA-3669-72x9-r9p3.
Affected Packages
-
PathGo VersionsSymbols
-
before v1.4.1
Aliases
References
- https://github.com/gorilla/schema/security/advisories/GHSA-3669-72x9-r9p3
- https://github.com/gorilla/schema/commit/cd59f2f12cbdfa9c06aa63e425d1fe4a806967ff
- https://github.com/gorilla/schema/blob/main/decoder.go#L223
- https://vuln.go.dev/ID/GO-2024-2958.json
Credits
- @AlexVasiluta
Feedback
See anything missing or incorrect?
Suggest an edit to this report.