VDB

RHBA-2020%3A4139

RHBA-2020%3A4139 PUBLISHED CVSS 5.900000095367432 MEDIUM

A flaw was found Go's net/http package. Servers using ReverseProxy from net/http in the Go standard library are vulnerable to a data race that results in a denial of service. The highest threat from this vulnerability is to system availability.

Risk Scores

CVSS 3.1
5.900000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Red Hatopenshift-service-mesh/3scale-istio-adapter-rhel8@sha256:744e2aa874312795ffb248721b1a0ad65bdaeee641e6f75e809106aec1cdb108_amd64 as a component of OpenShift Service Mesh 1.0*

Timeline

  • Sep 30, 2020 CVE Published
  • Mar 27, 2026 CVE Updated
  • Apr 30, 2026 Security Advisory
  • Apr 30, 2026 Security Advisory
  • Apr 30, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›