Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix CVE-2022-32149 #209

Merged
merged 2 commits into from
Nov 10, 2022
Merged

Fix CVE-2022-32149 #209

merged 2 commits into from
Nov 10, 2022

Conversation

hanahmily
Copy link
Contributor

An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take significant time to parse.

https://www.cve.org/CVERecord?id=CVE-2022-32149

Signed-off-by: Gao Hongtao hanahmily@gmail.com

An attacker may cause a denial of service by crafting an
Accept-Language header which ParseAcceptLanguage will take
significant time to parse.

https://www.cve.org/CVERecord?id=CVE-2022-32149

Signed-off-by: Gao Hongtao <hanahmily@gmail.com>
@hanahmily hanahmily added dependencies Pull requests that update a dependency file vulnerability This issue or PR relates to vulnerabilities labels Nov 10, 2022
@hanahmily hanahmily added this to the 0.3.0 milestone Nov 10, 2022
@hanahmily hanahmily merged commit e8d30e0 into main Nov 10, 2022
@hanahmily hanahmily deleted the cve branch November 10, 2022 14:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file vulnerability This issue or PR relates to vulnerabilities
Projects
None yet
3 participants