An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take significant time to parse.
References
Link Resource
https://go.dev/cl/442235 Vendor Advisory
https://go.dev/issue/56152 Issue Tracking Third Party Advisory
https://groups.google.com/g/golang-announce/c/-hjNw559_tE/m/KlGTfid5CAAJ Mailing List Third Party Advisory
https://pkg.go.dev/vuln/GO-2022-1059 Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: Go

Published: 2022-10-14T00:00:00

Updated: 2023-06-12T19:12:44.090Z

Reserved: 2022-05-31T00:00:00


Link: CVE-2022-32149

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-10-14T15:15:34.543

Modified: 2022-10-18T17:41:31.897


Link: CVE-2022-32149

JSON object: View

cve-icon Redhat Information

No data.

CWE