HomeDefault status
unaffected
Any version before 0.53.0
affected
Default status
unaffected
Any version before 1.25.10
affected
1.26.0-0 (semver) before 1.26.3
affected
Description
When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.
Problem types
CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')
Product status
Any version before 0.53.0
Any version before 1.25.10
1.26.0-0 (semver) before 1.26.3
Credits
Marwan Atia (marwansamir688@gmail.com)
References
groups.google.com/g/golang-announce/c/qcCIEXso47M