Impact
The vulnerability lies in the Go net/http package’s handling of the HTTP Range header. When a request contains a large number of small ranges, the server parses them all, consuming excessive CPU time. The absence of a limit means an attacker can craft a request that forces the server to perform a large amount of work, potentially exhausting available CPU cycles. This flaw does not grant code execution or data disclosure; its effect is limited to service availability loss due to resource exhaustion.
Affected Systems
All applications built with the Go standard library, specifically those that use FileServer, ServeContent or ServeFile functions, are affected. The vulnerability applies to any server or service that accepts Range headers via net/http. No particular Go release is specified, so any version prior to the fix that includes the unbounded parsing logic is potentially impacted.
Risk and Exploitability
The CVSS score is not provided, and the Exploit Prediction Scoring System value is not available. The vulnerability is not listed in CISA’s KEV catalogue. Attackers can exploit it by sending HTTP requests with a Range header containing a large number of small ranges, which forces the server to iterate over each range and thus increase CPU usage. Because the flaw lies in input parsing, the attack can be performed remotely over the network without privileged access. The lack of proactive limits makes the vulnerability moderately easy to exploit, presenting a low to moderate risk in absence of mitigation.
OpenCVE Enrichment