VDB

RHSA-2022%3A0163

RHSA-2022%3A0163 PUBLISHED CVSS 7.5 HIGH

There's an uncontrolled resource consumption flaw in golang's net/http library in the canonicalHeader() function. An attacker who submits specially crafted requests to applications linked with net/http's http2 functionality could cause excessive resource consumption that could lead to a denial of service or otherwise impact to system performance and resources.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Red Hatcryostat-20-tech-preview/cryostat-rhel8-operator@sha256:146c219295547fb31a7b6a00f6ca94c9f61d89d110d1b80c12c66c64ba7d3692_amd64 as a component of Cryostat 2 on RHEL 8cryostat-20-tech-preview/cryostat-rhel8-operator@sha256:146c219295547fb31a7b6a00f6ca94c9f61d89d110d1b80c12c66c64ba7d3692_amd64
Red Hatcryostat-20-tech-preview/cryostat-operator-bundle@sha256:7e22170562b9a35a66eaf9f3e05e9214581dda56a8f1a9c55a7cb81bd3d3cafa_amd64 as a component of Cryostat 2 on RHEL 8cryostat-20-tech-preview/cryostat-operator-bundle@sha256:7e22170562b9a35a66eaf9f3e05e9214581dda56a8f1a9c55a7cb81bd3d3cafa_amd64

Timeline

  • Jan 18, 2022 CVE Published
  • Mar 27, 2026 CVE Updated
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›