net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Debian
Subscribe
|
Debian Linux
Subscribe
|
|
Golang
Subscribe
|
Go
Subscribe
|
|
Netapp
Subscribe
|
Cloud Insights Telegraf
Subscribe
|
|
Redhat
Subscribe
|
Container Native Virtualization
Subscribe
Cryostat
Subscribe
Devtools
Subscribe
Enterprise Linux
Subscribe
Openshift
Subscribe
Openshift Data Foundation
Subscribe
Openshift Sandboxed Containers
Subscribe
Openstack
Subscribe
Rhel Eus
Subscribe
Rhmt
Subscribe
Serverless
Subscribe
Stf
Subscribe
Storage
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2891-1 | golang-1.8 security update |
Debian DLA |
DLA-2892-1 | golang-1.7 security update |
Debian DLA |
DLA-3395-1 | golang-1.11 security update |
EUVD |
EUVD-2022-0700 | net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests. |
Github GHSA |
GHSA-vc3p-29h2-gpcp | golang.org/x/net/http2 allows uncontrolled memory consumption |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 17 Jun 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat stf
|
|
| CPEs | cpe:/a:redhat:service_telemetry_framework:1.4::el8 |
cpe:/a:redhat:stf:1.3::el8 cpe:/a:redhat:stf:1.4::el8 |
| Vendors & Products |
Redhat service Telemetry Framework
|
Redhat stf
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T04:32:12.278Z
Reserved: 2021-12-07T00:00:00
Link: CVE-2021-44716
No data.
Status : Modified
Published: 2022-01-01T05:15:08.307
Modified: 2024-11-21T06:31:26.960
Link: CVE-2021-44716
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Github GHSA