Skip to content

Malformed DNS message can cause infinite loop

Moderate
nmengin published GHSA-f7cq-5v43-8pwp May 23, 2024

Package

gomod Traefik (Go)

Affected versions

<= v2.11.2, <= v3.0.0

Patched versions

v2.11.3, v3.0.1

Description

Impact

There is a vulnerability in GO managing malformed DNS message, which impacts Traefik.
This vulnerability could be exploited to cause a denial of service.

References

Patches

Workarounds

No workaround.

For more information

If you have any questions or comments about this advisory, please open an issue.

Severity

Moderate

CVE ID

CVE-2024-24787

Weaknesses

No CWEs