Description
Uncontrolled recursion in Decoder.Decode in encoding/gob before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a message which contains deeply nested structures.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-52466 | Uncontrolled recursion in Decoder.Decode in encoding/gob before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a message which contains deeply nested structures. |
Ubuntu USN |
USN-6038-1 | Go vulnerabilities |
Ubuntu USN |
USN-6038-2 | Go vulnerabilities |
References
History
Fri, 06 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sun, 08 Sep 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat acm
Redhat multicluster Engine |
|
| CPEs | cpe:/a:redhat:acm:2.5::el8 cpe:/a:redhat:acm:2.6::el8 cpe:/a:redhat:multicluster_engine:2.1::el8 |
|
| Vendors & Products |
Redhat acm
Redhat multicluster Engine |
Mon, 19 Aug 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:acm:2.6::el8 cpe:/a:redhat:multicluster_engine:2.1::el8 |
|
| Vendors & Products |
Redhat acm
Redhat multicluster Engine |
Subscriptions
Golang
Subscribe
Go
Subscribe
Redhat
Subscribe
Acm
Subscribe
Ceph Storage
Subscribe
Container Native Virtualization
Subscribe
Devtools
Subscribe
Enterprise Linux
Subscribe
Multicluster Engine
Subscribe
Openshift Api Data Protection
Subscribe
Openshift Custom Metrics Autoscaler
Subscribe
Openshift Data Foundation
Subscribe
Openshift Secondary Scheduler
Subscribe
Openstack
Subscribe
Rhmt
Subscribe
Serverless
Subscribe
Service Mesh
Subscribe
Status: PUBLISHED
Assigner: Go
Published:
Updated: 2026-03-06T17:44:24.600Z
Reserved: 2022-05-12T00:00:00.000Z
Link: CVE-2022-30635
Updated: 2024-08-03T06:56:13.235Z
Status : Modified
Published: 2022-08-10T20:15:42.640
Modified: 2026-03-06T18:16:14.177
Link: CVE-2022-30635
OpenCVE Enrichment
No data.
EUVD
Ubuntu USN